GKE Pod Created With HostNetwork

Detects GKE pod create, update, or patch events that enable host network namespace sharing. HostNetwork grants access to the node network stack and can bypass namespace network policies. System identities and controller-owned workloads are excluded.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/06/30"
  3integration = ["gcp"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Detects GKE pod create, update, or patch events that enable host network namespace sharing. HostNetwork grants access to
 11the node network stack and can bypass namespace network policies. System identities and controller-owned workloads are
 12excluded.
 13"""
 14false_positives = [
 15    """
 16    Monitoring agents and CNI components may require hostNetwork. Exclude known platform identities after review.
 17    """,
 18]
 19index = ["logs-gcp.audit-*"]
 20language = "kuery"
 21license = "Elastic License v2"
 22name = "GKE Pod Created With HostNetwork"
 23note = """## Triage and analysis
 24
 25### Investigating GKE Pod Created With HostNetwork
 26
 27HostNetwork pods can observe or interact with node-local services. Validate the actor and workload purpose.
 28
 29### Investigation steps
 30
 31- Review `user.email`, pod name, namespace, and container images in `gcp.audit.request`.
 32- Hunt for secret access or exec from the same identity after the change.
 33
 34### False positives
 35
 36- Platform DaemonSets often use hostNetwork; controller ownerReferences exclusion reduces noise.
 37
 38## Setup
 39
 40The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule."""
 41references = [
 42    "https://kubernetes.io/docs/concepts/security/pod-security-standards/",
 43    "https://bishopfox.com/blog/kubernetes-pod-privilege-escalation",
 44]
 45risk_score = 47
 46rule_id = "0030f681-0142-4231-b728-49bb9fc12066"
 47severity = "medium"
 48tags = [
 49    "Domain: Cloud",
 50    "Domain: Kubernetes",
 51    "Data Source: GCP",
 52    "Data Source: Google Cloud Platform",
 53    "Use Case: Threat Detection",
 54    "Tactic: Privilege Escalation",
 55    "Tactic: Execution",
 56    "Resources: Investigation Guide",
 57    "Noise: Unknown",
 58    "Performance: Fast",
 59    "Profile: Recommended",
 60    "Threat: Container Escape",
 61    "Rule Type: Custom Query (KQL)",
 62    "Platform: GCP",
 63    "Domain: Containers",
 64    "Platform: Kubernetes",
 65]
 66timestamp_override = "event.ingested"
 67type = "query"
 68
 69query = '''
 70data_stream.dataset:gcp.audit and
 71event.action:("io.k8s.core.v1.pods.create" or "io.k8s.core.v1.pods.update" or "io.k8s.core.v1.pods.patch") and
 72gcp.audit.request.spec.hostNetwork:true and
 73not gcp.audit.request.metadata.ownerReferences.kind:("ReplicaSet" or "DaemonSet" or "StatefulSet") and
 74not user.email:system\:*
 75'''
 76
 77[[rule.threat]]
 78framework = "MITRE ATT&CK"
 79
 80[[rule.threat.technique]]
 81id = "T1611"
 82name = "Escape to Host"
 83reference = "https://attack.mitre.org/techniques/T1611/"
 84
 85[rule.threat.tactic]
 86id = "TA0004"
 87name = "Privilege Escalation"
 88reference = "https://attack.mitre.org/tactics/TA0004/"
 89
 90[[rule.threat]]
 91framework = "MITRE ATT&CK"
 92
 93[[rule.threat.technique]]
 94id = "T1610"
 95name = "Deploy Container"
 96reference = "https://attack.mitre.org/techniques/T1610/"
 97
 98[rule.threat.tactic]
 99id = "TA0002"
100name = "Execution"
101reference = "https://attack.mitre.org/tactics/TA0002/"

Triage and analysis

Investigating GKE Pod Created With HostNetwork

HostNetwork pods can observe or interact with node-local services. Validate the actor and workload purpose.

Investigation steps

  • Review user.email, pod name, namespace, and container images in gcp.audit.request.
  • Hunt for secret access or exec from the same identity after the change.

False positives

  • Platform DaemonSets often use hostNetwork; controller ownerReferences exclusion reduces noise.

Setup

The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.

References

Related rules

to-top