GKE API Request Failure Burst by User

Detects bursts of failed GKE API requests from a single user identity within a five-minute window. Repeated authorization failures across multiple actions can indicate credential stuffing, RBAC probing, or reconnaissance with stolen tokens.

Elastic rule (View on GitHub)

 1[metadata]
 2creation_date = "2026/06/30"
 3integration = ["gcp"]
 4maturity = "production"
 5min_stack_comments = "MV_CONTAINS was added to ES|QL in 9.2.0 and is not available on 8.19; 9.3.0 is the lowest supported 9.x release."
 6min_stack_version = "9.3.0"
 7updated_date = "2026/09/22"
 8
 9[rule]
10author = ["Elastic"]
11description = """
12Detects bursts of failed GKE API requests from a single user identity within a five-minute window. Repeated authorization
13failures across multiple actions can indicate credential stuffing, RBAC probing, or reconnaissance with stolen tokens.
14"""
15from = "now-11m"
16interval = "5m"
17language = "esql"
18license = "Elastic License v2"
19name = "GKE API Request Failure Burst by User"
20note = """## Triage and analysis
21
22### Investigating GKE API Request Failure Burst by User
23
24The rule aggregates failed Kubernetes API calls per `user.email`, source IP, and user agent in five-minute buckets and
25alerts when failures reach ten or more.
26
27### Investigation steps
28
29- Review `Esql.actions` and `Esql.resources` for targeted API operations.
30- Validate whether the identity should exist and whether the source IP is expected.
31- Hunt for later successful calls indicating privilege escalation.
32
33### False positives
34
35- Misconfigured automation or CI jobs with stale credentials may generate bursts; exclude known service accounts.
36
37## Setup
38
39The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule."""
40references = [
41    "https://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging",
42    "https://attack.mitre.org/techniques/T1613/",
43]
44risk_score = 47
45rule_id = "94556bc7-e057-4759-9e49-fa79ee366101"
46severity = "medium"
47tags = [
48    "Domain: Cloud",
49    "Domain: Kubernetes",
50    "Data Source: GCP",
51    "Data Source: Google Cloud Platform",
52    "Use Case: Threat Detection",
53    "Tactic: Discovery",
54    "Resources: Investigation Guide",
55    "Noise: Unknown",
56    "Performance: Fast",
57    "Rule Type: ES|QL",
58    "Platform: GCP",
59    "Domain: Containers",
60    "Platform: Kubernetes",
61]
62timestamp_override = "event.ingested"
63type = "esql"
64
65query = '''
66from logs-gcp.audit-* metadata _id, _index, _version
67| eval Esql.time_interval = date_trunc(5 minutes, @timestamp)
68| where data_stream.dataset == "gcp.audit"
69    and service.name == "k8s.io"
70    and event.outcome == "failure"
71    and not mv_contains(event.type, "allowed")
72    and user.email is not null
73    and not to_string(user.email) rlike "(system:serviceaccount:|system:gke-spiffe-controller|system:kube-scheduler|system:node:).*"
74| stats
75    Esql.unique_actions = count_distinct(event.action),
76    Esql.failures_count = count(*),
77    Esql.actions = values(event.action),
78    Esql.resources = values(orchestrator.resource.name)
79  by user.email, source.ip, user_agent.original, data_stream.namespace, Esql.time_interval
80| where Esql.failures_count >= 10
81| keep Esql.*, user.email, source.ip, user_agent.original, data_stream.namespace
82'''
83
84[[rule.threat]]
85framework = "MITRE ATT&CK"
86
87[[rule.threat.technique]]
88id = "T1613"
89name = "Container and Resource Discovery"
90reference = "https://attack.mitre.org/techniques/T1613/"
91
92[rule.threat.tactic]
93id = "TA0007"
94name = "Discovery"
95reference = "https://attack.mitre.org/tactics/TA0007/"

Triage and analysis

Investigating GKE API Request Failure Burst by User

The rule aggregates failed Kubernetes API calls per user.email, source IP, and user agent in five-minute buckets and alerts when failures reach ten or more.

Investigation steps

  • Review Esql.actions and Esql.resources for targeted API operations.
  • Validate whether the identity should exist and whether the source IP is expected.
  • Hunt for later successful calls indicating privilege escalation.

False positives

  • Misconfigured automation or CI jobs with stale credentials may generate bursts; exclude known service accounts.

Setup

The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.

References

Related rules

to-top