Peirates is a post-exploitation Kubernetes exploitation framework with a focus on gathering service account tokens for lateral movement and privilege escalation. The tool is written in GoLang and publicly available on GitHub.
| Technique | Procedure example |
|---|---|
| T1046 Network Service Discovery |
Peirates can initiate a port scan against a given IP address. |
| T1078.004 Cloud Accounts |
Peirates can use stolen service account tokens to perform its operations. |
| T1528 Steal Application Access Token |
Peirates gathers Kubernetes service account tokens using a variety of techniques. |
| T1530 Data from Cloud Storage |
Peirates can dump the contents of AWS S3 buckets. It can also retrieve service account tokens from kOps buckets in Google Cloud Storage or S3. |
| T1550.001 Application Access Token |
Peirates can use stolen service account tokens to perform its operations. It also enables adversaries to switch between valid service accounts. |
| T1552.005 Cloud Instance Metadata API |
Peirates can query the query AWS and GCP metadata APIs for secrets. |
| T1552.007 Container API |
Peirates can query the Kubernetes API for secrets. |
| T1609 Container Administration Command |
Peirates can use `kubectl` or the Kubernetes API to run commands. |
| T1610 Deploy Container |
Peirates can deploy a pod that mounts its node’s root file system, then execute a command to create a reverse shell on the node. |
| T1611 Escape to Host |
Peirates can gain a reverse shell on a host node by mounting the Kubernetes hostPath. |
| T1613 Container and Resource Discovery |
Peirates can enumerate Kubernetes pods in a given namespace. |
| T1619 Cloud Storage Object Discovery |
Peirates can list AWS S3 buckets. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.