You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Privileged containers have all capabilities of the host machine. These privileged containers may perform actions directly on the host that they are running on. Ensure that this event is expected and occurs from a user account or IP address that normally works with privileged containers within the cluster. Customers are encouraged to set up an exclusion list for spec.securitycontext.capabilities for pods that are frequently going to be managed with privileged escalation.
Additional Details
Detail
Value
Type
Templated Match
Category
Privilege Escalation
Apply Risk to Entities
srcDevice_ip
Signal Name
Privileged Pod Created on AWS EKS by {{srcDevice_ip}}
Summary Expression
Privileged Pod Created on AWS EKS by {{srcDevice_ip}}