- Initial Access
Discover exposed API Server (6443) or Kubelet (10250).
- Enumeration
Enumerate pods, namespaces, RBAC permissions, and service accounts.
- Privilege Escalation
Abuse over-permissive RBAC to create or control workloads.
Malicious Pod Deployment
Mount the host filesystem using
hostPath.- Credential Access
Extract Secrets from environment variables or mounted volumes.
- Lateral Movement
Access databases, internal services, and additional cluster resources.
- Full Cluster Compromise
Gain host access, persistence, and potential control of the entire Kubernetes environment.
👀 به زودی یه مقاله کامل در مورد K8S Red Team توی قسمت بلاگ سایت منتشر می کنیم.
🆔 @vulncity