Kubernetes Pod Exec Potential Reverse Shell
Flags exec into a pod when the URL-decoded command payload resembles reverse-shell or bind-shell one-liners invocation patterns. Legitimate debug sessions sometimes use similar building blocks, but together these patterns align with post-exploitation interactive access and command-and-control.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/04/23"
3integration = ["kubernetes"]
4maturity = "production"
5min_stack_comments = "URL_DECODE was added to ES|QL in 9.2.0 and is not available on 8.19; 9.3.0 is the lowest supported 9.x release."
6min_stack_version = "9.3.0"
7updated_date = "2026/09/22"
8
9[rule]
10author = ["Elastic"]
11description = """
12Flags exec into a pod when the URL-decoded command payload resembles reverse-shell or bind-shell
13one-liners invocation patterns. Legitimate debug sessions sometimes use similar building blocks, but together
14these patterns align with post-exploitation interactive access and command-and-control.
15"""
16from = "now-6m"
17interval = "5m"
18language = "esql"
19license = "Elastic License v2"
20name = "Kubernetes Pod Exec Potential Reverse Shell"
21note = """## Triage and analysis
22
23### Investigating Kubernetes Pod Exec Potential Reverse Shell
24
25The rule inspects Kubernetes audit exec requestURI values, URL-decodes them, parses the command query fragment, and
26matches high-signal shell and socket idioms often used to obtain a fallback shell from inside a container.
27
28### Possible investigation steps
29
30- Identify the actor (kubernetes.audit.user.username, groups, impersonation), source IP, and user agent
31 (human kubectl vs automation).
32- Resolve the target namespace, pod, and container from kubernetes.audit.objectRef.* and correlate with
33 workload ownership and change tickets.
34- Pull the raw and decoded URI from the alert document and replay the inferred command in a sandbox only if policy
35 allows—otherwise rely on audit and platform logs.
36- Hunt nearby events from the same identity: secret reads, pods/exec to other workloads, RoleBinding
37 changes, or anonymous API use.
38
39### False positive analysis
40
41- Security training, CTF-style images, or vendor diagnostics may include bash redirection or /dev/tcp examples;
42 baseline approved images and break-glass accounts.
43- Some observability or mesh sidecars use socat or sockets in ways that could overlap; validate container image and
44 command lineage.
45
46### Response and remediation
47
48- If malicious, terminate the exec session, isolate the workload or node, rotate credentials reachable from the
49 pod, and revoke pods/exec for the abused principal unless strictly required.
50"""
51references = [
52 "https://attack.mitre.org/techniques/T1609/",
53 "https://attack.mitre.org/techniques/T1059/",
54]
55risk_score = 73
56rule_id = "f1a2b3c4-d5e6-4789-a012-3456789abc01"
57severity = "high"
58tags = [
59 "Data Source: Kubernetes",
60 "Data Source: Kubernetes API Server Audit Logs",
61 "Domain: Kubernetes",
62 "Platform: Kubernetes",
63 "Use Case: Threat Detection",
64 "Tactic: Execution",
65 "Tactic: Command and Control",
66 "Resources: Investigation Guide",
67 "Noise: Unknown",
68 "Performance: Normal",
69 "Profile: Recommended",
70 "Threat: Reverse Shell",
71 "Rule Type: ES|QL",
72 "Domain: Containers",
73 "Domain: Cloud",
74]
75timestamp_override = "event.ingested"
76type = "esql"
77query = '''
78FROM logs-kubernetes.audit_logs-* metadata _id, _index, _version
79| WHERE kubernetes.audit.objectRef.subresource == "exec"
80 AND kubernetes.audit.requestURI LIKE "*command=*"
81| EVAL Esql.decoded_uri = URL_DECODE(kubernetes.audit.requestURI)
82| GROK Esql.decoded_uri "%{DATA}/exec\\?%{DATA:raw_commands}&(?:container|stdin|stdout|stderr)=%{GREEDYDATA}"
83| EVAL command = REPLACE(raw_commands, "command=", "")
84| EVAL command = REPLACE(command, "&", " ")
85| EVAL Esql.executed_command = REPLACE(command, "\\+", " ")
86| WHERE Esql.executed_command IS NOT NULL AND command RLIKE """.*(/dev/tcp/|/dev/udp/|zsh/net/tcp|zsh/net/udp|nc\s+-e|ncat\s+-e|netcat\s+-e|nc\s.*\s-c\s|mkfifo|socat\s.*exec|socat\s.*pty|bash\s+-i\s+>&|0>&1|>&\s*/dev/tcp|import\s+socket.*connect|import\s+pty.*spawn|socket\.socket.*connect|IO::Socket::INET|fsockopen|TCPSocket\.new|/inet/tcp/).*""" AND
87 // local service health check patterns
88 NOT command RLIKE """.*/dev/tcp/(localhost|127\.0\.0\.1)/(8080|8443|9090|3000|5000|8888|80|443).*"""
89| KEEP Esql.*, user.name, user_agent.original, event.*, source.ip, kubernetes.audit.*, _id, _version, _index, data_stream.namespace
90'''
91
92[[rule.threat]]
93framework = "MITRE ATT&CK"
94
95[[rule.threat.technique]]
96id = "T1609"
97name = "Container Administration Command"
98reference = "https://attack.mitre.org/techniques/T1609/"
99
100[[rule.threat.technique]]
101id = "T1059"
102name = "Command and Scripting Interpreter"
103reference = "https://attack.mitre.org/techniques/T1059/"
104
105[rule.threat.tactic]
106id = "TA0002"
107name = "Execution"
108reference = "https://attack.mitre.org/tactics/TA0002/"
Triage and analysis
Investigating Kubernetes Pod Exec Potential Reverse Shell
The rule inspects Kubernetes audit exec requestURI values, URL-decodes them, parses the command query fragment, and matches high-signal shell and socket idioms often used to obtain a fallback shell from inside a container.
Possible investigation steps
- Identify the actor (kubernetes.audit.user.username, groups, impersonation), source IP, and user agent (human kubectl vs automation).
- Resolve the target namespace, pod, and container from kubernetes.audit.objectRef.* and correlate with workload ownership and change tickets.
- Pull the raw and decoded URI from the alert document and replay the inferred command in a sandbox only if policy allows—otherwise rely on audit and platform logs.
- Hunt nearby events from the same identity: secret reads, pods/exec to other workloads, RoleBinding changes, or anonymous API use.
False positive analysis
- Security training, CTF-style images, or vendor diagnostics may include bash redirection or /dev/tcp examples; baseline approved images and break-glass accounts.
- Some observability or mesh sidecars use socat or sockets in ways that could overlap; validate container image and command lineage.
Response and remediation
- If malicious, terminate the exec session, isolate the workload or node, rotate credentials reachable from the pod, and revoke pods/exec for the abused principal unless strictly required.
References
Related rules
- Kubernetes Pod Exec with Curl or Wget to HTTPS
- Kubernetes Pod Exec Cloud Instance Metadata Access
- Kubernetes Pod Exec Sensitive File or Credential Path Access
- GKE Pod Exec Potential Reverse Shell
- Azure AKS Pod Exec Potential Reverse Shell