PaloAltoNetworks / prisma-cloud-compute-sample-code

Example scripts, snippets, and other documents related to Prisma Cloud Compute
https://www.paloaltonetworks.com/prisma/cloud
Apache License 2.0
35 stars 41 forks source link

Add rule to catch suspicious assignments of controller serviceAccount #21

Closed yuvalavra closed 2 years ago

yuvalavra commented 2 years ago

Add admission rule that catches suspicious assignment of a controller serviceAccount to pods. This operation may be carried out by attackers that abuse compromised K8s credentials to attach a powerful controller service account to a pod in their control.

welcome-to-palo-alto-networks[bot] commented 2 years ago

:tada: Thanks for opening this pull request! We really appreciate contributors like you! :raised_hands:

yuvalavra commented 2 years ago

Hi @wfg, can you please merge this one?

welcome-to-palo-alto-networks[bot] commented 2 years ago

:tada: Congrats on getting your first pull request merged! We here at Palo Alto Networks are so grateful! :heart: