GKE User Exec into Pod
Description
Detects the first occurrence of a non-system GKE identity establishing an exec session into a pod. kubectl exec enables interactive command execution inside workloads and is a common post-compromise technique to access secrets and expand access.
Query · kuery
data_stream.dataset:gcp.audit and event.action:("io.k8s.core.v1.pods.exec.create" or "io.k8s.core.v1.pods.exec.get") and
not user.email:system\:*
Known false positives
- Administrators routinely exec into pods for troubleshooting. Baseline expected users and target pods, then exclude known break-glass identities.
Analyst notes
Investigating GKE User Exec into Pod
This new-terms rule alerts on the first exec into a given pod by a user identity in the lookback window.
Investigation steps
- Review
user.email,orchestrator.resource.name,source.ip, anduser_agent.original. - Determine whether the target pod holds sensitive data or cluster credentials.
- Correlate with secret access or RBAC changes from the same identity.
False positives
- Approved admin debugging; exclude stable operator identities after review.
Setup
The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.