Kubernetes Admission Controller Modification — Detection Rule

Detects when a modification (create, update or replace) action is taken that affects mutating or validating webhook configurations, as they can be used by an adversary to achieve persistence or exfiltrate access credentials.

Read the full analysis on IntelFusions