You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Kubernetes secrets may be deleted for legitimate purposes, ensure that this secrets created is from an IAM account that is expected to manage Kubernetes workloads on EKS.
Additional Details
Detail
Value
Type
Templated Match
Category
Credential Access
Apply Risk to Entities
srcDevice_ip
Signal Name
AWS EKS Secrets Deleted
Summary Expression
A Kubernetes secret was deleted within an AWS EKS cluster from {{srcDevice_ip}}