GKE Admission Webhook Created or Modified

Detects creation or modification of GKE mutating or validating admission webhook configurations by non-system identities. Malicious webhooks can inject workloads, block security tooling, or intercept API traffic for persistence and defense evasion.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/06/30"
  3integration = ["gcp"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Detects creation or modification of GKE mutating or validating admission webhook configurations by non-system identities.
 11Malicious webhooks can inject workloads, block security tooling, or intercept API traffic for persistence and defense
 12evasion.
 13"""
 14false_positives = [
 15    """
 16    GitOps and platform controllers (cert-manager, Gatekeeper, Kyverno, service mesh) legitimately manage webhooks.
 17    Validate change tickets and controller identities before tuning.
 18    """,
 19]
 20from = "now-9m"
 21index = ["logs-gcp.audit-*"]
 22language = "kuery"
 23license = "Elastic License v2"
 24name = "GKE Admission Webhook Created or Modified"
 25note = """## Triage and analysis
 26
 27### Investigating GKE Admission Webhook Created or Modified
 28
 29Review webhook name, actor, and clientConfig destination in `gcp.audit.request`.
 30
 31### Investigation steps
 32
 33- Confirm `user.email`, `event.action`, and webhook resource name.
 34- Inspect webhook URL or in-cluster service target for external endpoints.
 35- Hunt for pod mutations or blocked security deployments after the change.
 36
 37### False positives
 38
 39- Approved controller upgrades during change windows.
 40
 41## Setup
 42
 43The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule."""
 44references = [
 45    "https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/",
 46]
 47risk_score = 47
 48rule_id = "4886ce11-fca5-433f-bbb9-e33e410ef9ae"
 49severity = "medium"
 50tags = [
 51    "Domain: Cloud",
 52    "Domain: Kubernetes",
 53    "Data Source: GCP",
 54    "Data Source: Google Cloud Platform",
 55    "Use Case: Threat Detection",
 56    "Tactic: Persistence",
 57    "Tactic: Defense Evasion",
 58    "Resources: Investigation Guide",
 59    "Noise: Low",
 60    "Performance: Normal",
 61    "Rule Type: Custom Query (KQL)",
 62    "Platform: GCP",
 63    "Domain: Containers",
 64    "Platform: Kubernetes",
 65]
 66timestamp_override = "event.ingested"
 67type = "query"
 68
 69query = '''
 70data_stream.dataset:gcp.audit and event.outcome:success and event.action:(
 71  "io.k8s.admissionregistration.v1.mutatingwebhookconfigurations.create" or
 72  "io.k8s.admissionregistration.v1.mutatingwebhookconfigurations.update" or
 73  "io.k8s.admissionregistration.v1.mutatingwebhookconfigurations.patch" or
 74  "io.k8s.admissionregistration.v1.validatingwebhookconfigurations.create" or
 75  "io.k8s.admissionregistration.v1.validatingwebhookconfigurations.update" or
 76  "io.k8s.admissionregistration.v1.validatingwebhookconfigurations.patch"
 77) and not user.email:(
 78  "system:kube-controller-manager" or "system:kube-scheduler" or system\:serviceaccount\:kube-system\:* or
 79  system\:serviceaccount\:gke-managed-system\:* or system\:serviceaccount\:cert-manager\:* or
 80  system\:serviceaccount\:gatekeeper-system\:* or system\:serviceaccount\:kyverno\:* or "system:addon-manager" or
 81  *-operator or *-cainjector or *-webhook or *argocd* or "system:gke-common-webhooks"
 82)
 83'''
 84
 85[[rule.threat]]
 86framework = "MITRE ATT&CK"
 87
 88[[rule.threat.technique]]
 89id = "T1546"
 90name = "Event Triggered Execution"
 91reference = "https://attack.mitre.org/techniques/T1546/"
 92
 93[rule.threat.tactic]
 94id = "TA0003"
 95name = "Persistence"
 96reference = "https://attack.mitre.org/tactics/TA0003/"
 97
 98[[rule.threat]]
 99framework = "MITRE ATT&CK"
100
101[[rule.threat.technique]]
102id = "T1562"
103name = "Impair Defenses"
104reference = "https://attack.mitre.org/techniques/T1562/"
105
106[rule.threat.tactic]
107id = "TA0005"
108name = "Defense Evasion"
109reference = "https://attack.mitre.org/tactics/TA0005/"

Triage and analysis

Investigating GKE Admission Webhook Created or Modified

Review webhook name, actor, and clientConfig destination in gcp.audit.request.

Investigation steps

  • Confirm user.email, event.action, and webhook resource name.
  • Inspect webhook URL or in-cluster service target for external endpoints.
  • Hunt for pod mutations or blocked security deployments after the change.

False positives

  • Approved controller upgrades during change windows.

Setup

The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.

References

Related rules

to-top