GKE Suspicious Self-Subject Review via Service Account

Detects GKE service account or node identities invoking self-subject access or rules review APIs. Non-human identities rarely enumerate their own permissions outside known controllers; this can indicate stolen tokens probing effective RBAC.

Elastic rule (View on GitHub)

 1[metadata]
 2creation_date = "2026/06/30"
 3integration = ["gcp"]
 4maturity = "production"
 5updated_date = "2026/09/18"
 6
 7[rule]
 8author = ["Elastic"]
 9description = """
10Detects GKE service account or node identities invoking self-subject access or rules review APIs. Non-human identities
11rarely enumerate their own permissions outside known controllers; this can indicate stolen tokens probing effective RBAC.
12"""
13false_positives = [
14    """
15    Some controllers and admin impersonation workflows legitimately submit self-subject reviews. Excluded identities
16    include common Argo and Datadog service accounts.
17    """,
18]
19index = ["logs-gcp.audit-*"]
20language = "kuery"
21license = "Elastic License v2"
22name = "GKE Suspicious Self-Subject Review via Service Account"
23note = """## Triage and analysis
24
25### Investigating GKE Suspicious Self-Subject Review via Service Account
26
27Review the calling service account or node identity and subsequent API activity.
28
29### Investigation steps
30
31- Confirm `user.email` and `event.action` (selfsubjectaccessreviews or selfsubjectrulesreviews).
32- Correlate with denied requests, secret access, or RBAC changes from the same identity.
33
34### False positives
35
36- Known observability or workflow controllers; extend exclusions if needed.
37
38## Setup
39
40The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule."""
41references = [
42    "https://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access",
43]
44risk_score = 21
45rule_id = "2302fb59-5201-46ec-b433-6044adb37b0b"
46severity = "low"
47tags = [
48    "Domain: Cloud",
49    "Domain: Kubernetes",
50    "Data Source: GCP",
51    "Data Source: Google Cloud Platform",
52    "Use Case: Threat Detection",
53    "Tactic: Discovery",
54    "Resources: Investigation Guide",
55    "Noise: Unknown",
56    "Performance: Fast",
57    "Rule Type: Custom Query (KQL)",
58    "Platform: GCP",
59    "Domain: Containers",
60    "Platform: Kubernetes",
61]
62timestamp_override = "event.ingested"
63type = "query"
64
65query = '''
66data_stream.dataset:gcp.audit and service.name:k8s.io and event.action:(io.k8s.authorization.v1.selfsubjectaccessreviews.create or io.k8s.authorization.v1.selfsubjectrulesreviews.create) and user.email:((system\:node\:* or system\:serviceaccount\:*) and not ("system:serviceaccount:default:argo-argo-workflows-server" or "system:serviceaccount:default:argo-argo-workflows-workflow-controller" or system\:serviceaccount\:*\:datadog-kube-state-metrics))
67'''
68
69[[rule.threat]]
70framework = "MITRE ATT&CK"
71
72[[rule.threat.technique]]
73id = "T1069"
74name = "Permission Groups Discovery"
75reference = "https://attack.mitre.org/techniques/T1069/"
76
77[[rule.threat.technique.subtechnique]]
78id = "T1069.003"
79name = "Cloud Groups"
80reference = "https://attack.mitre.org/techniques/T1069/003/"
81
82[[rule.threat.technique]]
83id = "T1613"
84name = "Container and Resource Discovery"
85reference = "https://attack.mitre.org/techniques/T1613/"
86
87[rule.threat.tactic]
88id = "TA0007"
89name = "Discovery"
90reference = "https://attack.mitre.org/tactics/TA0007/"

Triage and analysis

Investigating GKE Suspicious Self-Subject Review via Service Account

Review the calling service account or node identity and subsequent API activity.

Investigation steps

  • Confirm user.email and event.action (selfsubjectaccessreviews or selfsubjectrulesreviews).
  • Correlate with denied requests, secret access, or RBAC changes from the same identity.

False positives

  • Known observability or workflow controllers; extend exclusions if needed.

Setup

The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.

References

Related rules

to-top