Chained Kubernetes API enumeration followed by Slack search recon
Detects a suspicious sequence of events where Kubernetes API resources (namespaces, secrets, configmaps, pods, or nodes) are enumerated, followed by a search query against the Slack API, indicative of a potential reconnaissance phase or sandbox escape attempt.
Suricata

