Before creating anything, read the node. The runtime tools list every pod, container, and image on the node and expose their configuration, which reveals mounts, environment secrets, and which workloads are worth targeting or exec-ing into.
crictl ps -a # all containers on the node
crictl inspect <id> | jq '.info.config.envs, .info.runtimeSpec.mounts'
crictl exec -it <id> sh # shell into a running container
ctr -n k8s.io images list
Exploitation notes#
- Container
envsandmountsfrequently hold service-account tokens, database passwords, and cloud credentials. crictl execinto a more privileged workload is a lateral step that needs only socket access, not the API.- Enumeration is quiet and read-only; use it to choose a target before the noisier create-and-escape step.