kevmap

Log sources › kubernetes:apiserver

kubernetes:apiserver

Inverted view: what can be detected if this is the log you have. Containers

10
channels
9
analytics
9
techniques
4
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Pod spec with hostPath or privileged securityContext DC0092 Volume Modification AN0612 1
Resource creation and update logs DC0028 Image Metadata AN0986 1
authentication.k8s.io/v1beta1 DC0002 User Account Authentication AN1268 1
create/exec: Kubernetes API calls to exec into containers or create pods from curl, kubectl, or SDK clients DC0072 Container Creation AN0233 1
exec into pod followed by secret retrieval via API DC0032 Process Creation AN0571 1
get/list requests to /api/v1/secrets or /api/v1/namespaces/*/serviceaccounts DC0002 User Account Authentication AN0571 1
kubectl exec or kubelet API calls targeting running pods DC0032 Process Creation AN0177 1
list or get requests against pods, deployments, or nodes DC0037 Pod Enumeration AN1352 1
serviceAccount token used in API requests not tied to workload identity DC0007 Web Credential Usage AN0530 1
verb=create, resource=cronjobs, group=batch DC0001 Scheduled Job Creation AN0582 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1036.005 Match Legitimate Resource Name or Locationstealth211
T1053.007 Container Orchestration Jobexecution, persistence, privilege escalation00
T1059.013 Container CLI/APIexecution00
T1110.004 Credential Stuffingcredential access00
T1550.001 Application Access Tokenlateral movement40
T1552.007 Container APIcredential access40
T1609 Container Administration Commandexecution30
T1611 Escape to Hostprivilege escalation23
T1613 Container and Resource Discoverydiscovery10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2023-26360Adobe ColdFusion T1036.005 Mapped
CVE-2025-22224VMware ESXi and Workstation T1611 Mapped
CVE-2025-22225VMware ESXi T1611 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1611 Mapped