pack:
  id: cloud-metadata-k8s-recon
  version: 1.0.0
  created: 2026-07-29T00:00:00Z
  provenance:
    sources:
      - internal_research
      - incident_report
    incident_refs:
      - hugging-face-rogue-agent-2026
  minimum_engine_version: 0.6.0
  rules:
    - id: CLOUD-RECON-001
      severity: high
      name: Cloud metadata endpoint access
      description: >
        Detects any attempt to reach cloud instance metadata endpoints —
        169.254.169.254 (AWS/GCP/Azure IMDS), 169.254.170.2 (ECS task
        metadata), or fd00:ec2::254 (EC2 IPv6 metadata) — whether via a
        direct network connection or a curl/wget/HTTP-client command
        line. This is the exact step used to harvest instance-role
        credentials in the Hugging Face rogue agent incident, entirely
        without touching disk.
      response_level: block
      type: single
      conditions:
        action_type: EXECUTE
        target_pattern: "**169.254.169.254**"

    - id: CLOUD-RECON-002
      severity: high
      name: Kubernetes service-account token access
      description: >
        Detects reads of the Kubernetes service-account token mounted
        into every pod at /var/run/secrets/kubernetes.io/token (or any
        sibling file under that directory, e.g. ca.crt/namespace). This
        token carries whatever RBAC permissions the pod's service
        account has and is a primary credential-harvesting target.
      response_level: block
      type: single
      conditions:
        action_type: READ
        target_pattern: "**/var/run/secrets/kubernetes.io/**"

    - id: CLOUD-RECON-003
      severity: medium
      name: Kubernetes permission/resource enumeration
      description: >
        Detects a single kubectl/K8s-API enumeration command (kubectl
        auth can-i, kubectl get secrets/pods, or a direct call to the
        in-cluster API server) — reconnaissance of cluster resources and
        RBAC permissions. A single occurrence is alert-only; repeated
        occurrences within the session escalate to block (see
        cloud-recon-k8s-enum-repeated below).
      response_level: warn
      type: single
      conditions:
        action_type: EXECUTE
        target_pattern: "**kubectl auth can-i**"

    - id: CLOUD-RECON-004
      severity: high
      name: Cloud CLI credential file access
      description: >
        Detects reads of known cloud CLI credential file locations —
        ~/.aws/credentials, ~/.aws/config, ~/.config/gcloud/*,
        ~/.azure/* — long-lived cloud credentials at rest on disk.
      response_level: block
      type: single
      conditions:
        action_type: READ
        target_pattern: "**/.aws/credentials"

    - id: CLOUD-RECON-005
      severity: medium
      name: Cloud credential environment variable access
      description: >
        Detects attempts to read cloud credential environment variables
        (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY,
        GOOGLE_APPLICATION_CREDENTIALS, AZURE_CLIENT_SECRET, and
        similar) — a single read is advisory; bulk reads of several such
        variables at once are a stronger harvesting signal (handled by
        the cloud-recon-guard.js hardcoded detector, which counts
        distinct variables per request).
      response_level: warn
      type: single
      conditions:
        action_type: EXECUTE
        target_pattern: "**AWS_SECRET_ACCESS_KEY**"

    - id: cloud-recon-k8s-enum-repeated
      severity: high
      name: Repeated Kubernetes enumeration chain
      description: >
        Detects Kubernetes permission/resource enumeration occurring
        three or more times within the session window — a pattern of
        active cluster reconnaissance rather than an isolated lookup,
        escalating from alert-only (CLOUD-RECON-003) to block.
      response_level: block
      type: sequence
      sequence:
        - action_type: EXECUTE
          step: cluster_permission_query
          conditions: {}
        - action_type: EXECUTE
          step: cluster_permission_query
          conditions: {}
        - action_type: EXECUTE
          step: cluster_permission_query
          conditions: {}
      window_seconds: 300
      action: block_and_isolate

    - id: cloud-recon-full-chain
      severity: critical
      name: Kubernetes-to-cloud-metadata reconnaissance chain
      description: >
        Detects the full Hugging Face incident recon shape: reading the
        Kubernetes service-account token, then querying cluster
        permissions with it, then pulling cloud instance metadata — the
        complete pre-exfiltration reconnaissance sequence, performed
        before any credential is actually used elsewhere.
      response_level: block
      type: sequence
      sequence:
        - action_type: READ
          step: service_account_token_read
          conditions: {}
        - action_type: EXECUTE
          step: cluster_permission_query
          conditions: {}
        - action_type: EXECUTE
          step: cloud_metadata_access
          conditions: {}
      window_seconds: 300
      action: block_and_isolate

  signature: ""
