Clankerusecase
Kubernetes detection coverage
← Back to main site
Home/ Targets/ Kubernetes

Kubernetes detections

Clankerusecase tracks 66 detection use cases covering the Kubernetes attack surface across 41 MITRE ATT&CK techniques.

Detections targeting Kubernetes clusters — audit logs, pod creation, RBAC, container escapes.

Open Detection Library → View on the matrix
66Use cases
41Techniques
18Articles
6Kill-chain phases

Top techniques on Kubernetes (25)

Reconnaissance (1)

[LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container Bespoke recon · hunting DSΣPDDCS

Delivery (4)

[LLM] Permissive RBAC grants create on logging-operator flows/outputs resources Bespoke delivery · hunting SΣPDD [LLM] Anomalous EnvoyExtensionPolicy submitter / suspicious policy name Bespoke delivery · hunting SΣPDD [LLM] kubectl apply of attacker-crafted Rancher import URL (authImage payload delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] Docker / Kubernetes pull of compromised ghcr.io/elementary-data/elementary image Bespoke delivery · alerting DSΣPDDCS

Exploitation (9)

[WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [LLM] Fluentd config injection via Flow/Output CRD record_transformer (block-close + @type exec) Bespoke exploit · alerting SΣPDD [LLM] EnvoyExtensionPolicy Lua with double-slash path traversal to secrets (CVE-2026-53713) Bespoke exploit · alerting SΣPDD [LLM] EnvoyExtensionPolicy Lua invoking os/io/debug file primitives Bespoke exploit · hunting SΣPDD [LLM] Nuclio CronJob container args carry injected shell (CVE-2026-52831 header/body OS command injection) Bespoke exploit · alerting SPDD [LLM] Fission Environment CRD create/update with dangerous SecurityContext on standalone container (CVE-2026-50566) Bespoke exploit · alerting SΣPDD Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Bespoke exploit · hunting DSP Article-specific behavioural hunt — CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran Bespoke exploit · hunting DSP [LLM] Anonymous access to Kubernetes aggregated API (CVE-2018-1002105 exploit surface) Bespoke exploit · hunting SΣPDDCW

Installation (8)

Kubernetes ClusterRole / binding deleted Internal install · alerting DD Kubernetes pod created with privileged flag Internal install · alerting DD Kubernetes RBAC role binding created Internal install · alerting DD Kubernetes admission webhook configuration modified Internal install · alerting DD [LLM] Orphaned Nuclio CronJob without ownerReferences (CVE-2026-52831 persistence) Bespoke install · hunting SPDD [LLM] Privileged / dangerous-capability pod scheduled in Fission function/builder namespace by executor SA Bespoke install · alerting SPDD [LLM] TeamPCP rope.pyz Dropper Infection Markers on Linux Bespoke install · alerting DSΣPDDCS [LLM] Malicious privileged DaemonSet apply in kube-system (host-provisioner-iran / host-provisioner-std / kamikaze) Bespoke install · alerting DSΣPDDCS

Command & Control (1)

[LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) Bespoke c2 · alerting DSΣPDDCS

Actions on Objectives (43)

Kubernetes Secret accessed Internal actions · alerting DD [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP Amazon EKS Kubernetes Pod scan detection ESCU actions · hunting P Kubernetes Abuse of Secret by Unusual Location ESCU actions · hunting P Kubernetes Abuse of Secret by Unusual User Agent ESCU actions · hunting P Kubernetes Abuse of Secret by Unusual User Group ESCU actions · hunting P Kubernetes Abuse of Secret by Unusual User Name ESCU actions · hunting P Kubernetes Anomalous Inbound Network Activity from Process ESCU actions · hunting P Kubernetes Anomalous Inbound Outbound Network IO ESCU actions · hunting P Kubernetes Anomalous Inbound to Outbound Network IO Ratio ESCU actions · hunting P Kubernetes Anomalous Outbound Network Activity from Process ESCU actions · hunting P Kubernetes Anomalous Traffic on Network Edge ESCU actions · hunting P Kubernetes Create or Update Privileged Pod ESCU actions · hunting P Kubernetes Cron Job Creation ESCU actions · hunting P Kubernetes DaemonSet Deployed ESCU actions · hunting P Kubernetes newly seen TCP edge ESCU actions · hunting P Kubernetes newly seen UDP edge ESCU actions · hunting P Kubernetes Node Port Creation ESCU actions · hunting P Kubernetes Pod Created in Default Namespace ESCU actions · hunting P Kubernetes Pod With Host Network Attachment ESCU actions · hunting P Kubernetes Previously Unseen Container Image Name ESCU actions · hunting P Kubernetes Previously Unseen Process ESCU actions · hunting P Kubernetes Process Running From New Path ESCU actions · hunting P Kubernetes Process with Anomalous Resource Utilisation ESCU actions · hunting P Kubernetes Process with Resource Ratio Anomalies ESCU actions · hunting P Kubernetes Shell Running on Worker Node ESCU actions · hunting P Kubernetes Shell Running on Worker Node with CPU Activity ESCU actions · hunting P Kubernetes Suspicious Image Pulling ESCU actions · hunting P Kubernetes Unauthorized Access ESCU actions · hunting P Hunting for Log4Shell ESCU actions · hunting P GCP Kubernetes cluster scan detection ESCU actions · alerting P [LLM] Build/attestation process egress to non-canonical OCI registry (@sigstore/oci cred leak, CVE-2026-59891) Bespoke actions · hunting DSPCS [LLM] Leaked SA token / file contents in EnvoyExtensionPolicy status (CVE-2026-53713 disclosure) Bespoke actions · alerting SΣPDD [LLM] Envoy Gateway ServiceAccount token reuse for anomalous K8s API actions Bespoke actions · hunting SΣPDD [LLM] Fleet valuesFrom cross-namespace secret/configmap reference (CVE-2026-44935) Bespoke actions · hunting SΣPDD [LLM] Fleet agent service account reads secrets across multiple namespaces (CVE-2026-44935) Bespoke actions · alerting SPDD [LLM] Lateral movement via aws ssm send-command or kubectl exec spawned by python/node Bespoke actions · alerting DSΣPDDCSCW [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) Bespoke actions · hunting DSPDDCS [LLM] Kubernetes propagation via kubectl staged in /tmp (kubectl exec / get secrets) Bespoke actions · alerting DSΣPDDCS [LLM] Kubernetes privileged-pod DaemonSet fan-out from compromised LiteLLM workload Bespoke actions · hunting SPDD [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host Bespoke actions · alerting DSΣPDD [LLM] Anonymous principal reaching kubelet/pod proxy subresources (CVE-2018-1002105 tunnel) Bespoke actions · alerting SΣPDDCW

Recent articles citing Kubernetes-targeted detections