Title:Potential Sidecar Injection Into Running Deployment Status:test Description:Detects attempts to inject a sidecar container into a running deployment.
A sidecar container is an additional container within a pod, that resides alongside the main container.
One way to add containers to running resources like Deployments/DeamonSets/StatefulSets, is via a "kubectl patch" operation.
By injecting a new container within a legitimate pod, an attacker can run their code and hide their activity, instead of running their own separated pod in the cluster.
References: -https://kubernetes.io/docs/tasks/manage-kubernetes-objects/update-api-object-kubectl-patch -https://microsoft.github.io/Threat-Matrix-for-Kubernetes/techniques/Sidecar%20Injection/ Author: Leo Tsaousis (@laripping) Date: 2024-03-26 modified:None Tags: