GKE API Request Failure Burst by User
Detects bursts of failed GKE API requests from a single user identity within a five-minute window. Repeated authorization failures across multiple actions can indicate credential stuffing, RBAC probing, or reconnaissance with stolen tokens.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/06/30"
3integration = ["gcp"]
4maturity = "production"
5min_stack_comments = "MV_CONTAINS was added to ES|QL in 9.2.0 and is not available on 8.19; 9.3.0 is the lowest supported 9.x release."
6min_stack_version = "9.3.0"
7updated_date = "2026/09/22"
8
9[rule]
10author = ["Elastic"]
11description = """
12Detects bursts of failed GKE API requests from a single user identity within a five-minute window. Repeated authorization
13failures across multiple actions can indicate credential stuffing, RBAC probing, or reconnaissance with stolen tokens.
14"""
15from = "now-11m"
16interval = "5m"
17language = "esql"
18license = "Elastic License v2"
19name = "GKE API Request Failure Burst by User"
20note = """## Triage and analysis
21
22### Investigating GKE API Request Failure Burst by User
23
24The rule aggregates failed Kubernetes API calls per `user.email`, source IP, and user agent in five-minute buckets and
25alerts when failures reach ten or more.
26
27### Investigation steps
28
29- Review `Esql.actions` and `Esql.resources` for targeted API operations.
30- Validate whether the identity should exist and whether the source IP is expected.
31- Hunt for later successful calls indicating privilege escalation.
32
33### False positives
34
35- Misconfigured automation or CI jobs with stale credentials may generate bursts; exclude known service accounts.
36
37## Setup
38
39The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule."""
40references = [
41 "https://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging",
42 "https://attack.mitre.org/techniques/T1613/",
43]
44risk_score = 47
45rule_id = "94556bc7-e057-4759-9e49-fa79ee366101"
46severity = "medium"
47tags = [
48 "Domain: Cloud",
49 "Domain: Kubernetes",
50 "Data Source: GCP",
51 "Data Source: Google Cloud Platform",
52 "Use Case: Threat Detection",
53 "Tactic: Discovery",
54 "Resources: Investigation Guide",
55 "Noise: Unknown",
56 "Performance: Fast",
57 "Rule Type: ES|QL",
58 "Platform: GCP",
59 "Domain: Containers",
60 "Platform: Kubernetes",
61]
62timestamp_override = "event.ingested"
63type = "esql"
64
65query = '''
66from logs-gcp.audit-* metadata _id, _index, _version
67| eval Esql.time_interval = date_trunc(5 minutes, @timestamp)
68| where data_stream.dataset == "gcp.audit"
69 and service.name == "k8s.io"
70 and event.outcome == "failure"
71 and not mv_contains(event.type, "allowed")
72 and user.email is not null
73 and not to_string(user.email) rlike "(system:serviceaccount:|system:gke-spiffe-controller|system:kube-scheduler|system:node:).*"
74| stats
75 Esql.unique_actions = count_distinct(event.action),
76 Esql.failures_count = count(*),
77 Esql.actions = values(event.action),
78 Esql.resources = values(orchestrator.resource.name)
79 by user.email, source.ip, user_agent.original, data_stream.namespace, Esql.time_interval
80| where Esql.failures_count >= 10
81| keep Esql.*, user.email, source.ip, user_agent.original, data_stream.namespace
82'''
83
84[[rule.threat]]
85framework = "MITRE ATT&CK"
86
87[[rule.threat.technique]]
88id = "T1613"
89name = "Container and Resource Discovery"
90reference = "https://attack.mitre.org/techniques/T1613/"
91
92[rule.threat.tactic]
93id = "TA0007"
94name = "Discovery"
95reference = "https://attack.mitre.org/tactics/TA0007/"
Triage and analysis
Investigating GKE API Request Failure Burst by User
The rule aggregates failed Kubernetes API calls per user.email, source IP, and user agent in five-minute buckets and
alerts when failures reach ten or more.
Investigation steps
- Review
Esql.actionsandEsql.resourcesfor targeted API operations. - Validate whether the identity should exist and whether the source IP is expected.
- Hunt for later successful calls indicating privilege escalation.
False positives
- Misconfigured automation or CI jobs with stale credentials may generate bursts; exclude known service accounts.
Setup
The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.
References
Related rules
- GKE Certificate Signing Request Self-Approved
- GKE Endpoint Permission Enumeration
- GKE Multi-Resource Discovery
- GKE Suspicious Self-Subject Review via Service Account
- GKE API Request Impersonating Privileged Identity