crictl and ctr enumeration

Before creating anything, read the node. The runtime tools list every pod, container, and image on the node and expose their configuration, which reveals mounts, environment secrets, and which workloads are worth targeting or exec-ing into.

bash
crictl ps -a                                  # all containers on the node
crictl inspect <id> | jq '.info.config.envs, .info.runtimeSpec.mounts'
crictl exec -it <id> sh                       # shell into a running container
ctr -n k8s.io images list

Exploitation notes#

  • Container envs and mounts frequently hold service-account tokens, database passwords, and cloud credentials.
  • crictl exec into a more privileged workload is a lateral step that needs only socket access, not the API.
  • Enumeration is quiet and read-only; use it to choose a target before the noisier create-and-escape step.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more