InGuardians. (2022, January 5). Peirates GitHub. Retrieved February 8, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1046 Network Service Discovery |
ToolPeirates | Peirates can initiate a port scan against a given IP address. |
| T1078.004 Cloud Accounts |
ToolPeirates | Peirates can use stolen service account tokens to perform its operations. |
| T1528 Steal Application Access Token |
ToolPeirates | Peirates gathers Kubernetes service account tokens using a variety of techniques. |
| T1530 Data from Cloud Storage |
ToolPeirates | Peirates can dump the contents of AWS S3 buckets. It can also retrieve service account tokens from kOps buckets in Google Cloud Storage or S3. |
| T1550.001 Application Access Token |
ToolPeirates | Peirates can use stolen service account tokens to perform its operations. It also enables adversaries to switch between valid service accounts. |
| T1552.005 Cloud Instance Metadata API |
ToolPeirates | Peirates can query the query AWS and GCP metadata APIs for secrets. |
| T1552.007 Container API |
ToolPeirates | Peirates can query the Kubernetes API for secrets. |
| T1609 Container Administration Command |
ToolPeirates | Peirates can use `kubectl` or the Kubernetes API to run commands. |
| T1610 Deploy Container |
ToolPeirates | Peirates can deploy a pod that mounts its node’s root file system, then execute a command to create a reverse shell on the node. |
| T1611 Escape to Host |
ToolPeirates | Peirates can gain a reverse shell on a host node by mounting the Kubernetes hostPath. |
| T1613 Container and Resource Discovery |
ToolPeirates | Peirates can enumerate Kubernetes pods in a given namespace. |
| T1619 Cloud Storage Object Discovery |
ToolPeirates | Peirates can list AWS S3 buckets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.