Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- detections
Loading detections…
Loading detections
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
Loading detections…
Detects when the same GKE identity creates or modifies a Role or ClusterRole with high-risk permissions (wildcard access, RBAC escalation verbs, or access to secrets / privileged APIs) and also creates or patches a DaemonSet, Deployment, or CronJob within five minutes. This correlation is consistent with RBAC-based privilege escalation followed by payload deployment.
Published to signed-in readers
The query as its source wrote it, its canonical form, and the content hash that pins this exact revision.