Lateral movement

Lateral movement in Kubernetes is credential reuse along the cluster's own trust edges. A pod holds a service-account token that authenticates to the API server; the API exposes secrets and more tokens; the flat pod network reaches other workloads directly; and a pod's cloud workload identity reaches the surrounding cloud account. Each move takes a credential the cluster issued for a legitimate purpose and uses it to reach the next target, so movement rarely needs an exploit, only enumeration and reuse.

bash
# the token you hold, what it reaches, and the network around you
kubectl auth can-i --list
kubectl get secrets --all-namespaces 2>/dev/null | head
kubectl get endpoints -A 2>/dev/null | head

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more