Microsoft.ContainerService/managedClusters/runCommand/action
Microsoft.ContainerService/managedClusters/runCommand/action
Event
AKS Run Command uses a command pod to run tools such as kubectl and Helm through Azure management APIs. It requires runcommand/action permission and commandResults/read to retrieve results. It avoids a direct client connection to a private API endpoint, but pod scheduling, cluster configuration, authentication context, and network requirements still matter.
Security Context
Unauthorized shell commands can support T1059. This operation alone does not prove lateral movement or execution inside an existing workload container. Accepted requests can fail later, and command output is limited to 512 kB.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.ContainerService/managedClusters/runCommand/action. Inspect status/subStatus and related records; asynchronous acceptance is not final resource-state evidence. Request bodies are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Initiating identity and recorded authorization context; corroborate effective permissions. |
resourceId, correlationId | Target and related operation records. |
status, subStatus | Outcome and asynchronous acceptance versus completion. |
properties.requestbody, httpRequest | Configuration or command and endpoint when present; these fields are not guaranteed. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify approved command content, management permissions, and the cluster authentication/token context.
- Follow the asynchronous operation to its result, exit code, and logs; inspect command-pod scheduling failures.
- For secret queries, use Kubernetes audit and command-result evidence to determine what was actually returned; do not assume a complete dump.
Sample Event
Synthetic scenario. The request contains an inert kubectl secrets query. HTTP 202 indicates acceptance, not successful retrieval. Optional context/token fields and all output are omitted.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.ContainerService/managedClusters/runCommand/action", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "aud": "https://management.core.windows.net/", "iss": "https://sts.windows.net/10000000-0000-4000-8000-000000000001/", "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud" }, "correlationId": "90000000-0000-4000-8000-000011000100", "description": "", "eventDataId": "90000000-0000-4000-8000-000011000101", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T22:58:42.7382194Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000011000110", "operationName": { "value": "Microsoft.ContainerService/managedClusters/runCommand/action", "localizedValue": "Run a command against an AKS Managed Cluster" }, "resourceGroupName": "rg-occamy-pipeline", "resourceProviderName": { "value": "Microsoft.ContainerService", "localizedValue": "Microsoft.ContainerService" }, "resourceType": { "value": "Microsoft.ContainerService/managedClusters", "localizedValue": "Microsoft.ContainerService/managedClusters" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "Accepted", "localizedValue": "Accepted (HTTP Status Code: 202)" }, "submissionTimestamp": "2026-04-15T22:58:43.0218732Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Accepted", "serviceRequestId": null, "requestbody": "{\"command\":\"kubectl get secrets --all-namespaces -o yaml\"}", "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod", "message": "Microsoft.ContainerService/managedClusters/runCommand/action", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": [], "httpRequest": { "clientRequestId": "90000000-0000-4000-8000-000011000111", "clientIpAddress": "203.0.113.66", "method": "POST", "url": "https://management.azure.com/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-occamy-pipeline/providers/Microsoft.ContainerService/managedClusters/aks-occamy-prod/runCommand?api-version=2024-02-01" }, "identity": null}Sources
MITRE ATT&CK Mapping
Tactics: Execution
- T1059 — Command and Scripting Interpreter — Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface a...