Container API

T1552.007

Sub-technique of T1552 Unsecured Credentials.View on attack.mitre.org

About this technique

Adversaries may gather credentials via APIs within a containers environment. APIs in these environments, such as the Docker API and Kubernetes APIs, allow a user to remotely manage their container resources and cluster components.

An adversary may access the Docker API to collect logs that contain credentials to cloud, container, and various other resources in the environment. An adversary with sufficient permissions, such as via a pod's service account, may also use the Kubernetes API to retrieve credentials from the Kubernetes API server. These credentials may include those needed for Docker API authentication or secrets from Kubernetes cluster components.

Detection rules8

Rules on DetectionCode tagged with T1552.007.

Sigma4

RuleLevelLog source
Azure Kubernetes Admission Controllermediumazure / NULL
Google Cloud Kubernetes Admission Controllermediumgcp / NULL
Kubernetes Admission Controller Modificationmediumkubernetes / NULL
Kubernetes Secrets Enumerationlowkubernetes / application

Splunk4

RuleTypeRiskData source
Kubernetes Abuse of Secret by Unusual LocationAnomalyNULLKubernetes Audit
Kubernetes Abuse of Secret by Unusual User AgentAnomalyNULLKubernetes Audit
Kubernetes Abuse of Secret by Unusual User GroupAnomalyNULLKubernetes Audit
Kubernetes Abuse of Secret by Unusual User NameAnomalyNULLKubernetes Audit

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples3

Software3

Used byProcedure example
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered unsecured API keys stored in container orchestrators.

ToolPeirates

Peirates can query the Kubernetes API for secrets.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can query the Kubernetes API for credentials.

References3

  1. Docker API Open source
    Docker. (n.d.). Docker Engine API v1.41 Reference. Retrieved March 31, 2021.
  2. Kubernetes API Open source
    The Kubernetes Authors. (n.d.). The Kubernetes API. Retrieved March 29, 2021.
  3. Unit 42 Unsecured Docker Daemons Open source
    Chen, J.. (2020, January 29). Attacker's Tactics and Techniques in Unsecured Docker Daemons Revealed. Retrieved March 31, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.