GKE Cluster-Admin Role Binding Created or Modified
Detects creation or modification of a GKE ClusterRoleBinding that grants the cluster-admin ClusterRole, providing unrestricted cluster access and enabling rapid privilege escalation or persistence.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/06/30"
3integration = ["gcp"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Detects creation or modification of a GKE ClusterRoleBinding that grants the cluster-admin ClusterRole, providing
11unrestricted cluster access and enabling rapid privilege escalation or persistence.
12"""
13index = ["logs-gcp.audit-*"]
14language = "kuery"
15license = "Elastic License v2"
16name = "GKE Cluster-Admin Role Binding Created or Modified"
17note = """## Triage and analysis
18
19### Investigating GKE Cluster-Admin Role Binding Created or Modified
20
21Identify who created or changed the binding and which subject received cluster-admin.
22
23### Investigation steps
24
25- Review `client.user.email`, `source.ip`, and `gcp.audit.request` for the bound subject.
26- Hunt for secret reads, privileged pod creation, or webhook changes from the same actor or new subject.
27
28### False positives
29
30- Bootstrap and recovery may recreate cluster-admin bindings via `system:apiserver` during control plane reconciliation (excluded).
31
32"""
33setup = "The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule."
34references = [
35 "https://cloud.google.com/kubernetes-engine/docs/how-to/role-based-access-control",
36 "https://heilancoos.github.io/research/2025/12/16/kubernetes.html#overly-permissive-role-based-access-control",
37]
38risk_score = 47
39rule_id = "16708afb-4904-4d3c-af78-63640a075cb0"
40severity = "medium"
41tags = [
42 "Domain: Cloud",
43 "Domain: Kubernetes",
44 "Data Source: GCP",
45 "Data Source: Google Cloud Platform",
46 "Use Case: Threat Detection",
47 "Tactic: Persistence",
48 "Tactic: Privilege Escalation",
49 "Resources: Investigation Guide",
50 "Noise: Unknown",
51 "Performance: Fast",
52 "Rule Type: Custom Query (KQL)",
53 "Platform: GCP",
54 "Domain: Containers",
55 "Platform: Kubernetes",
56]
57timestamp_override = "event.ingested"
58type = "query"
59
60query = '''
61data_stream.dataset:gcp.audit and service.name:"k8s.io" and event.outcome:success and
62event.action:(
63 "io.k8s.authorization.rbac.v1.clusterrolebindings.create" or
64 "io.k8s.authorization.rbac.v1.clusterrolebindings.patch" or
65 "io.k8s.authorization.rbac.v1.clusterrolebindings.update"
66) and gcp.audit.request.kind:"ClusterRoleBinding" and
67gcp.audit.resource_name:"rbac.authorization.k8s.io/v1/clusterrolebindings/cluster-admin" and
68not client.user.email:"system:apiserver"
69'''
70
71[[rule.threat]]
72framework = "MITRE ATT&CK"
73
74[[rule.threat.technique]]
75id = "T1098"
76name = "Account Manipulation"
77reference = "https://attack.mitre.org/techniques/T1098/"
78
79[[rule.threat.technique.subtechnique]]
80id = "T1098.006"
81name = "Additional Container Cluster Roles"
82reference = "https://attack.mitre.org/techniques/T1098/006/"
83
84[rule.threat.tactic]
85id = "TA0003"
86name = "Persistence"
87reference = "https://attack.mitre.org/tactics/TA0003/"
88
89[[rule.threat]]
90framework = "MITRE ATT&CK"
91
92[[rule.threat.technique]]
93id = "T1098"
94name = "Account Manipulation"
95reference = "https://attack.mitre.org/techniques/T1098/"
96
97[[rule.threat.technique.subtechnique]]
98id = "T1098.006"
99name = "Additional Container Cluster Roles"
100reference = "https://attack.mitre.org/techniques/T1098/006/"
101
102[rule.threat.tactic]
103id = "TA0004"
104name = "Privilege Escalation"
105reference = "https://attack.mitre.org/tactics/TA0004/"
106
107[rule.investigation_fields]
108field_names = [
109 "@timestamp",
110 "client.user.email",
111 "source.ip",
112 "user_agent.original",
113 "event.action",
114 "event.outcome",
115 "gcp.audit.resource_name",
116 "gcp.audit.request.kind",
117 "gcp.audit.request.roleRef.name",
118 "gcp.audit.request.subjects.name",
119 "data_stream.namespace",
120]
Triage and analysis
Investigating GKE Cluster-Admin Role Binding Created or Modified
Identify who created or changed the binding and which subject received cluster-admin.
Investigation steps
- Review
client.user.email,source.ip, andgcp.audit.requestfor the bound subject. - Hunt for secret reads, privileged pod creation, or webhook changes from the same actor or new subject.
False positives
- Bootstrap and recovery may recreate cluster-admin bindings via
system:apiserverduring control plane reconciliation (excluded).
References
Related rules
- GKE Certificate Signing Request API Client Signer Requested
- GKE API Request Impersonating Privileged Identity
- GKE Certificate Signing Request Self-Approved
- GKE Client Certificate Signing Request Created or Approved
- GKE Creation of a RoleBinding Referencing a ServiceAccount