Most Popular Detection 2026: K8s pods/exec or pods/attach into Privileged/HostPID/HostNetwork Pods
Detects 'kubectl exec' or 'kubectl attach' requests targeting pods configured with dangerous security contexts (privileged, hostPID, or hostNetwork). The rule filters out known CI/CD service accounts to focus on potentially malicious manual or unauthorized programmatic access, which often serves as a precursor to container breakout or host-level compromise.
Microsoft Sentinel (KQL)

