Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1552.007

T1552.007Container API

T1552.007 — Container API is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 8 detection use cases covering it and 2 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
8Use cases
2Articles
0Sub-techniques
1Tactic

Use cases covering this technique (8)

Kubernetes Secret accessed Internal actions · alerting DD Kubernetes Abuse of Secret by Unusual Location ESCU actions · hunting P Kubernetes Abuse of Secret by Unusual User Agent ESCU actions · hunting P Kubernetes Abuse of Secret by Unusual User Group ESCU actions · hunting P Kubernetes Abuse of Secret by Unusual User Name ESCU actions · hunting P [LLM] Fleet valuesFrom cross-namespace secret/configmap reference (CVE-2026-44935) Bespoke actions · hunting SΣPDD [LLM] Fleet agent service account reads secrets across multiple namespaces (CVE-2026-44935) Bespoke actions · alerting SPDD [LLM] Cloud instance-metadata harvesting from npm/node install context (Miasma credential theft) Bespoke actions · alerting DSPCS

Articles citing this technique (2)