Tag
high
advisory
Excessive ClusterRole Permissions in hawtio-operator
3 TTPs 1 CVEThe hawtio-operator contains an overly permissive ClusterRole configuration that enables an attacker who compromises the operator pod to access all Secrets across the Kubernetes cluster.
hawtio-operator
oauth
privilege-escalation
token-harvesting
cloud-security
3t
1c
high
advisory
Multi-Cloud CLI Token and Credential Access via Command-Line Harvesting
3 rules 2 TTPsThis rule detects command-line activity indicative of credential access across multiple cloud platforms (GCP, Azure, AWS, GitHub, DigitalOcean, Oracle, Kubernetes), looking for specific commands used to print or access tokens and credentials, flagging hosts where multiple cloud targets are accessed within a five-minute window, suggesting potential credential harvesting activity.
gcloud +6
credential-access
cloud
cli
token-harvesting
3r
2t