Automated actor enumerates Kubernetes secrets and Slack search post-breakout
This rule detects potentially malicious activity where an identity performs enumeration of Kubernetes secrets or configmaps and subsequently performs a search action within Slack from the same IP address within a one-hour window. This behavioral pattern is indicative of post-breakout reconnaissance, where a compromised identity or token is used to exfiltrate sensitive cloud configuration data and then perform internal reconnaissance in SaaS collaboration tools to identify further targets or credentials.
Microsoft Sentinel (KQL)

