Skip to content

[Tuning] Kubernetes Secrets List Across Cluster or Sensitive Namespaces - #6692

Merged
Samirbous merged 5 commits into
mainfrom
Samirbous-patch-3
Aug 26, 2026
Merged

[Tuning] Kubernetes Secrets List Across Cluster or Sensitive Namespaces#6692
Samirbous merged 5 commits into
mainfrom
Samirbous-patch-3

Conversation

@Samirbous

Copy link
Copy Markdown
Contributor

Exclude few noisy FP patterns by SA.

@Samirbous Samirbous self-assigned this Aug 24, 2026
Copilot AI lite review requested due to automatic review settings August 24, 2026 09:45
@Samirbous Samirbous added Rule: Tuning tweaking or tuning an existing rule Integration: Kubernetes Kubernetes Integration labels Aug 24, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tunes the existing Kubernetes audit-log detection rule “Kubernetes Secrets List Across Cluster or Sensitive Namespaces” to reduce false positives by adding additional service account / group-based exclusions, and updates the rule metadata updated_date to reflect the tuning date.

Changes:

  • Updated rule updated_date to 2026/08/24.
  • Expanded exclusions to suppress alerts generated by additional service accounts and serviceaccount groups (e.g., Argo CD and Elastic namespaces).

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Samirbous
Samirbous merged commit f09d477 into main Aug 26, 2026
13 of 17 checks passed
@Samirbous
Samirbous deleted the Samirbous-patch-3 branch August 26, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport: auto Integration: Kubernetes Kubernetes Integration Rule: Tuning tweaking or tuning an existing rule

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants