killchain.sh
Pick an attack surface to explore its tactics & techniques tree.
- ☸KubernetesAttack techniques against Kubernetes clusters — recon through impact.31 techniquesReconnaissance
- Cluster dump
- Exposed API server
- Exposed dashboards / kubelet
- Cloud metadata enumeration
- Container registry recon
Initial Access- Vulnerable container image
- Exposed Ingress / misconfig
- RBAC misconfiguration
- Leaked kubeconfig / credentials
Execution- kubectl exec into pod
- Malicious CronJob / Job
- Static pod injection
Privilege Escalation- Privileged pod / hostPath mount
- hostPID / hostNetwork abuse
- ServiceAccount token abuse
- Node abuse via DaemonSet
- Pivot to cloud IAM role
Credential Access- etcd secrets dump
- Cloud instance metadata (IMDS)
- Secrets in env vars / volumes
Lateral Movement- Cross-namespace pivoting
- Node-to-cloud pivot
- Service mesh abuse
Persistence- Malicious admission webhook
- Backdoored ServiceAccount
- Rogue DaemonSet
Defense Evasion- Falco / audit log tampering
- Namespace / label masquerading
Exfiltration / Impact- Data exfil via pod egress
- Cryptomining deployment
- Resource DoS