⎈Kubernetes detections
Clankerusecase tracks 66 detection use cases covering the Kubernetes attack surface across 41 MITRE ATT&CK techniques.
Detections targeting Kubernetes clusters — audit logs, pod creation, RBAC, container escapes.
66Use cases
41Techniques
18Articles
6Kill-chain phases
Top techniques on Kubernetes (25)
T1204User Execution20T1552.001Credentials In Files8T1552.007Container API7T1190Exploit Public-Facing Application7T1610Deploy Container7T1611Escape to Host6T1609Container Administration Command5T1526Cloud Service Discovery4T1528Steal Application Access Token4T1098Account Manipulation3T1613Container and Resource Discovery3T1078.004Cloud Accounts3T1204.002Malicious File3T1105Ingress Tool Transfer3T1548Abuse Elevation Control Mechanism2T1555Credentials from Password Stores2T1041Exfiltration Over C2 Channel2T1059Command and Scripting Interpreter2T1068Exploitation for Privilege Escalation2T1053.007Container Orchestration Job2T1059.004Unix Shell2T1531Account Access Removal1T1554Compromise Host Software Binary1T1555.003Credentials from Web Browsers1T1539Steal Web Session Cookie1