{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/elastic-kubernetes-service-eks/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elastic Kubernetes Service (EKS)"],"_cs_severities":["medium"],"_cs_tags":["cloud","kubernetes","persistence","privilege-escalation","aws"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAmazon EKS Access Entries allow administrators to map IAM principals to Kubernetes permissions, simplifying cluster authentication. Attackers can abuse this mechanism to gain persistent access or escalate privileges by creating, updating, or associating access policies with malicious or compromised IAM principals. Because these entries modify authentication mappings outside of standard in-cluster Kubernetes RBAC objects, they can be used to bypass existing security controls and maintain a foothold within the cluster environment. Defenders should monitor for unexpected changes to these entries that do not correlate with known infrastructure-as-code or automated deployment activities.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of EKS Access Entries can allow an attacker to gain persistent, unauthorized access to a Kubernetes cluster, potentially leading to unauthorized data access, lateral movement, or service disruption. Monitoring for these changes helps identify unauthorized privilege escalation or persistence efforts before they are leveraged for further malicious activity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement monitoring for the specific CloudTrail actions listed in the Sigma rule below to detect unauthorized cluster access changes.\u003c/li\u003e\n\u003cli\u003eReview and baseline existing IAM roles utilized by deployment pipelines (e.g., terraform, eksctl) to reduce false positives in detection logic.\u003c/li\u003e\n\u003cli\u003ePair these alerts with Kubernetes audit log monitoring to track subsequent API activity performed by identities tied to newly created or updated access entries.\u003c/li\u003e\n\u003cli\u003eUse AWS IAM and Service Control Policies (SCPs) to restrict access to EKS configuration APIs to authorized administrators only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T01:06:43Z","date_published":"2026-09-19T01:06:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-eks-access-entry-modification/","summary":"Detection of unauthorized Amazon EKS Access Entry modifications via AWS CloudTrail, which may be used by attackers to achieve persistent access or privilege escalation in Kubernetes clusters.","title":"Monitoring Unauthorized Amazon EKS Access Entry Modifications","url":"https://feed.craftedsignal.io/briefs/2026-09-eks-access-entry-modification/"}],"language":"en","title":"CraftedSignal Threat Feed - Elastic Kubernetes Service (EKS)","version":"https://jsonfeed.org/version/1.1"}