Sub-technique of T1552 Unsecured Credentials.View on attack.mitre.org
Adversaries may gather credentials via APIs within a containers environment. APIs in these environments, such as the Docker API and Kubernetes APIs, allow a user to remotely manage their container resources and cluster components.
An adversary may access the Docker API to collect logs that contain credentials to cloud, container, and various other resources in the environment. An adversary with sufficient permissions, such as via a pod's service account, may also use the Kubernetes API to retrieve credentials from the Kubernetes API server. These credentials may include those needed for Docker API authentication or secrets from Kubernetes cluster components.
Rules on DetectionCode tagged with T1552.007.
| Rule | Level | Log source |
|---|---|---|
| Azure Kubernetes Admission Controller | medium | azure / NULL |
| Google Cloud Kubernetes Admission Controller | medium | gcp / NULL |
| Kubernetes Admission Controller Modification | medium | kubernetes / NULL |
| Kubernetes Secrets Enumeration | low | kubernetes / application |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Kubernetes Abuse of Secret by Unusual Location | Anomaly | NULL | Kubernetes Audit |
| Kubernetes Abuse of Secret by Unusual User Agent | Anomaly | NULL | Kubernetes Audit |
| Kubernetes Abuse of Secret by Unusual User Group | Anomaly | NULL | Kubernetes Audit |
| Kubernetes Abuse of Secret by Unusual User Name | Anomaly | NULL | Kubernetes Audit |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered unsecured API keys stored in container orchestrators. |
| ToolPeirates | Peirates can query the Kubernetes API for secrets. |
| MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can query the Kubernetes API for credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.