Kubernetes

Most Kubernetes attacks start from a single compromised pod and climb. A pod carries an identity (a service-account token), sits on a flat network, and runs on a node that holds credentials for the whole cluster. The path is familiar: enumerate, reach exposed components, escalate through RBAC, escape to the node, move laterally, and persist. Escaping the pod to its node uses the runtime-agnostic primitives in Container escape; this area is the cluster-level attack model around them.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more