GKE Container Created with Excessive Linux Capabilities
Description
Detects GKE pod creation with dangerous Linux capabilities that are commonly abused in container escape techniques. Standalone pods are included; controller-owned ReplicaSet, DaemonSet, and StatefulSet workloads are excluded.
Query · kuery
data_stream.dataset:gcp.audit and event.action:"io.k8s.core.v1.pods.create" and event.outcome:success and
gcp.audit.request.spec.containers.securityContext.capabilities.add:(
"BPF" or "DAC_READ_SEARCH" or "NET_ADMIN" or "SYS_ADMIN" or "SYS_BOOT" or "SYS_MODULE" or "SYS_PTRACE" or "SYS_RAWIO" or
"SYSLOG"
) and not gcp.audit.request.metadata.ownerReferences.kind:("ReplicaSet" or "DaemonSet" or "StatefulSet")
Known false positives
- Some platform or security images legitimately require elevated capabilities. Add image or namespace exceptions after review.
Analyst notes
Investigating GKE Container Created with Excessive Linux Capabilities
Capabilities such as SYS_ADMIN, NET_ADMIN, and BPF can enable host escape. Review gcp.audit.request.spec.containers
and the creating identity.
Investigation steps
- Confirm which capability was added and whether the image requires it.
- Review
user.email, namespace, and follow-on API activity from the same actor.
False positives
- Known DaemonSet or operator images may need capabilities; exclude after validation.
Setup
The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.