Create Service Account (kubernetes)
| Platform | Author | Last Update | 
|---|---|---|
| kubernetes | Leo Tsaousis | 2024-12-02 | 
Create a Kubernetes service account
MITRE IDs
Scope
This test case does not need Cluster-wide permissions
Required Permissions
-   apiGroups:    - ''    namespaced: true    resources:    - serviceaccounts    verbs:    - createRequired Parameters
| Name | Type | Description | Example Value | 
|---|---|---|---|
| serviceaccount | str | Name of the service account to create | leonidas-created-service | 
Attacker Action
kubectl create serviceaccount leonidas-created-serviceDetection Case
ELK query
When logs are ingested into ELK, the following query can be used to identify relevant events.
verb:create AND resource:serviceaccountsSigma Definition
---title: Create service accountid: e31bae15-83ed-473e-bf31-faf4f8a17d36status: experimentalauthor: Leo Tsaousisdate: 2024-12-02description: |  Create a Kubernetes service accountlogsource:  product: kubernetes  service: auditdetection:  selection:    verb: create
    resource: serviceaccounts
  condition: selectionlevel: lowtags:- attack.T1136references:- https://microsoft.github.io/Threat-Matrix-for-Kubernetes/techniques/container%20service%20account/