⎈Kubernetes detections
Clankerusecase tracks 60 detection use cases covering the Kubernetes attack surface across 43 MITRE ATT&CK techniques.
Detections targeting Kubernetes clusters — audit logs, pod creation, RBAC, container escapes.
60Use cases
43Techniques
17Articles
5Kill-chain phases
Top techniques on Kubernetes (25)
T1204User Execution20T1611Escape to Host10T1552.001Credentials In Files8T1610Deploy Container6T1552.007Container API5T1190Exploit Public-Facing Application4T1068Exploitation for Privilege Escalation4T1098Account Manipulation3T1526Cloud Service Discovery3T1078.004Cloud Accounts3T1105Ingress Tool Transfer3T1195.002Compromise Software Supply Chain3T1528Steal Application Access Token3T1555Credentials from Password Stores2T1555.003Credentials from Web Browsers2T1539Steal Web Session Cookie2T1041Exfiltration Over C2 Channel2T1059Command and Scripting Interpreter2T1552.005Cloud Instance Metadata API2T1059.006Python2T1059.004Unix Shell2T1071.001Web Protocols2T1613Container and Resource Discovery2T1204.002Malicious File2T1531Account Access Removal1