GKE Cluster-Admin Role Binding Created or Modified

Detects creation or modification of a GKE ClusterRoleBinding that grants the cluster-admin ClusterRole, providing unrestricted cluster access and enabling rapid privilege escalation or persistence.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/06/30"
  3integration = ["gcp"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Detects creation or modification of a GKE ClusterRoleBinding that grants the cluster-admin ClusterRole, providing
 11unrestricted cluster access and enabling rapid privilege escalation or persistence.
 12"""
 13index = ["logs-gcp.audit-*"]
 14language = "kuery"
 15license = "Elastic License v2"
 16name = "GKE Cluster-Admin Role Binding Created or Modified"
 17note = """## Triage and analysis
 18
 19### Investigating GKE Cluster-Admin Role Binding Created or Modified
 20
 21Identify who created or changed the binding and which subject received cluster-admin.
 22
 23### Investigation steps
 24
 25- Review `client.user.email`, `source.ip`, and `gcp.audit.request` for the bound subject.
 26- Hunt for secret reads, privileged pod creation, or webhook changes from the same actor or new subject.
 27
 28### False positives
 29
 30- Bootstrap and recovery may recreate cluster-admin bindings via `system:apiserver` during control plane reconciliation (excluded).
 31
 32"""
 33setup = "The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule."
 34references = [
 35    "https://cloud.google.com/kubernetes-engine/docs/how-to/role-based-access-control",
 36    "https://heilancoos.github.io/research/2025/12/16/kubernetes.html#overly-permissive-role-based-access-control",
 37]
 38risk_score = 47
 39rule_id = "16708afb-4904-4d3c-af78-63640a075cb0"
 40severity = "medium"
 41tags = [
 42    "Domain: Cloud",
 43    "Domain: Kubernetes",
 44    "Data Source: GCP",
 45    "Data Source: Google Cloud Platform",
 46    "Use Case: Threat Detection",
 47    "Tactic: Persistence",
 48    "Tactic: Privilege Escalation",
 49    "Resources: Investigation Guide",
 50    "Noise: Unknown",
 51    "Performance: Fast",
 52    "Rule Type: Custom Query (KQL)",
 53    "Platform: GCP",
 54    "Domain: Containers",
 55    "Platform: Kubernetes",
 56]
 57timestamp_override = "event.ingested"
 58type = "query"
 59
 60query = '''
 61data_stream.dataset:gcp.audit and service.name:"k8s.io" and event.outcome:success and
 62event.action:(
 63  "io.k8s.authorization.rbac.v1.clusterrolebindings.create" or
 64  "io.k8s.authorization.rbac.v1.clusterrolebindings.patch" or
 65  "io.k8s.authorization.rbac.v1.clusterrolebindings.update"
 66) and gcp.audit.request.kind:"ClusterRoleBinding" and
 67gcp.audit.resource_name:"rbac.authorization.k8s.io/v1/clusterrolebindings/cluster-admin" and
 68not client.user.email:"system:apiserver"
 69'''
 70
 71[[rule.threat]]
 72framework = "MITRE ATT&CK"
 73
 74[[rule.threat.technique]]
 75id = "T1098"
 76name = "Account Manipulation"
 77reference = "https://attack.mitre.org/techniques/T1098/"
 78
 79[[rule.threat.technique.subtechnique]]
 80id = "T1098.006"
 81name = "Additional Container Cluster Roles"
 82reference = "https://attack.mitre.org/techniques/T1098/006/"
 83
 84[rule.threat.tactic]
 85id = "TA0003"
 86name = "Persistence"
 87reference = "https://attack.mitre.org/tactics/TA0003/"
 88
 89[[rule.threat]]
 90framework = "MITRE ATT&CK"
 91
 92[[rule.threat.technique]]
 93id = "T1098"
 94name = "Account Manipulation"
 95reference = "https://attack.mitre.org/techniques/T1098/"
 96
 97[[rule.threat.technique.subtechnique]]
 98id = "T1098.006"
 99name = "Additional Container Cluster Roles"
100reference = "https://attack.mitre.org/techniques/T1098/006/"
101
102[rule.threat.tactic]
103id = "TA0004"
104name = "Privilege Escalation"
105reference = "https://attack.mitre.org/tactics/TA0004/"
106
107[rule.investigation_fields]
108field_names = [
109    "@timestamp",
110    "client.user.email",
111    "source.ip",
112    "user_agent.original",
113    "event.action",
114    "event.outcome",
115    "gcp.audit.resource_name",
116    "gcp.audit.request.kind",
117    "gcp.audit.request.roleRef.name",
118    "gcp.audit.request.subjects.name",
119    "data_stream.namespace",
120]

Triage and analysis

Investigating GKE Cluster-Admin Role Binding Created or Modified

Identify who created or changed the binding and which subject received cluster-admin.

Investigation steps

  • Review client.user.email, source.ip, and gcp.audit.request for the bound subject.
  • Hunt for secret reads, privileged pod creation, or webhook changes from the same actor or new subject.

False positives

  • Bootstrap and recovery may recreate cluster-admin bindings via system:apiserver during control plane reconciliation (excluded).

References

Related rules

to-top