GKE Pod Created With HostIPC

Detects GKE pod create, update, or patch events that enable host IPC namespace sharing. This exposes host inter-process communication mechanisms and can support privilege escalation. Controller-owned workloads are excluded.

Elastic rule (View on GitHub)

 1[metadata]
 2creation_date = "2026/06/30"
 3integration = ["gcp"]
 4maturity = "production"
 5updated_date = "2026/09/18"
 6
 7[rule]
 8author = ["Elastic"]
 9description = """
10Detects GKE pod create, update, or patch events that enable host IPC namespace sharing. This exposes host inter-process
11communication mechanisms and can support privilege escalation. Controller-owned workloads are excluded.
12"""
13false_positives = [
14    """
15    Administrators may enable hostIPC for legitimate debugging. Exclude trusted users or namespaces after baselining.
16    """,
17]
18index = ["logs-gcp.audit-*"]
19language = "kuery"
20license = "Elastic License v2"
21name = "GKE Pod Created With HostIPC"
22note = """## Triage and analysis
23
24### Investigating GKE Pod Created With HostIPC
25
26Host IPC lets a pod interact with host IPC facilities. Review the pod spec, actor, and whether the change was expected.
27
28### Investigation steps
29
30- Confirm `gcp.audit.request.spec.hostIPC` and targeted namespace or pod.
31- Review `user.email` and correlate with other risky pod modifications.
32
33### False positives
34
35- Break-glass debugging on nodes; allowlist known admin identities.
36
37## Setup
38
39The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule."""
40references = [
41    "https://kubernetes.io/docs/concepts/security/pod-security-standards/",
42    "https://bishopfox.com/blog/kubernetes-pod-privilege-escalation",
43]
44risk_score = 47
45rule_id = "fde4efad-9cd0-4fa4-84c8-0e3b6fc957b4"
46severity = "medium"
47tags = [
48    "Domain: Cloud",
49    "Domain: Kubernetes",
50    "Data Source: GCP",
51    "Data Source: Google Cloud Platform",
52    "Use Case: Threat Detection",
53    "Tactic: Privilege Escalation",
54    "Tactic: Execution",
55    "Resources: Investigation Guide",
56    "Noise: Unknown",
57    "Performance: Fast",
58    "Profile: Recommended",
59    "Threat: Container Escape",
60    "Rule Type: Custom Query (KQL)",
61    "Platform: GCP",
62    "Domain: Containers",
63    "Platform: Kubernetes",
64]
65timestamp_override = "event.ingested"
66type = "query"
67
68query = '''
69data_stream.dataset:gcp.audit and event.outcome:success and
70event.action:("io.k8s.core.v1.pods.create" or "io.k8s.core.v1.pods.update" or "io.k8s.core.v1.pods.patch") and
71gcp.audit.request.spec.hostIPC:true and
72not gcp.audit.request.metadata.ownerReferences.kind:("ReplicaSet" or "DaemonSet" or "StatefulSet")
73'''
74
75[[rule.threat]]
76framework = "MITRE ATT&CK"
77
78[[rule.threat.technique]]
79id = "T1611"
80name = "Escape to Host"
81reference = "https://attack.mitre.org/techniques/T1611/"
82
83[rule.threat.tactic]
84id = "TA0004"
85name = "Privilege Escalation"
86reference = "https://attack.mitre.org/tactics/TA0004/"
87
88[[rule.threat]]
89framework = "MITRE ATT&CK"
90
91[[rule.threat.technique]]
92id = "T1610"
93name = "Deploy Container"
94reference = "https://attack.mitre.org/techniques/T1610/"
95
96[rule.threat.tactic]
97id = "TA0002"
98name = "Execution"
99reference = "https://attack.mitre.org/tactics/TA0002/"

Triage and analysis

Investigating GKE Pod Created With HostIPC

Host IPC lets a pod interact with host IPC facilities. Review the pod spec, actor, and whether the change was expected.

Investigation steps

  • Confirm gcp.audit.request.spec.hostIPC and targeted namespace or pod.
  • Review user.email and correlate with other risky pod modifications.

False positives

  • Break-glass debugging on nodes; allowlist known admin identities.

Setup

The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.

References

Related rules

to-top