Additional Container Cluster Roles

T1098.006

Sub-technique of T1098 Account Manipulation.View on attack.mitre.org

About this technique

An adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a container orchestration system. For example, an adversary with sufficient permissions may create a RoleBinding or a ClusterRoleBinding to bind a Role or ClusterRole to a Kubernetes account. Where attribute-based access control (ABAC) is in use, an adversary with sufficient permissions may modify a Kubernetes ABAC policy to give the target account additional permissions.

This account modification may immediately follow Create Account or other malicious account activity. Adversaries may also modify existing Valid Accounts that they have compromised.

Note that where container orchestration systems are deployed in cloud environments, as with Google Kubernetes Engine, Amazon Elastic Kubernetes Service, and Azure Kubernetes Service, cloud-based role-based access control (RBAC) assignments or ABAC policies can often be used in place of or in addition to local permission assignments. In these cases, this technique may be used in conjunction with Additional Cloud Roles.

Detection rules0

Rules on DetectionCode tagged with T1098.006.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References6

  1. AWS EKS IAM Roles for Service Accounts Open source
    Amazon Web Services. (n.d.). IAM roles for service accounts. Retrieved July 14, 2023.
  2. Aquasec Kubernetes Attack 2023 Open source
    Michael Katchinskiy, Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved July 14, 2023.
  3. Google Cloud Kubernetes IAM Open source
    Google Cloud. (n.d.). Create IAM policies. Retrieved July 14, 2023.
  4. Kuberentes ABAC Open source
    Kuberenets. (n.d.). Using ABAC Authorization. Retrieved July 14, 2023.
  5. Kubernetes RBAC Open source
    Kubernetes. (n.d.). Role Based Access Control Good Practices. Retrieved March 8, 2023.
  6. Microsoft Azure Kubernetes Service Service Accounts Open source
    Microsoft Azure. (2023, April 28). Access and identity options for Azure Kubernetes Service (AKS). Retrieved July 14, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.