Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

T1611 - k8s audit logs - nsenter container escape #788

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions datasets/attack_techniques/T1611/k8s_audit.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
author: Travis Lowe
id: b40cf657-6d9b-43a3-9a3d-a7efd9aad6fd
date: '2023-01-28'
description: 'Successful execution of a container escape command will allow an attacker to access host level resouces. In kubernetes this could lead to the entire cluster being compromised. This data set shows possible escapes.'
environment: custom
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1611/nsenter.json
sourcetypes:
- kube:apiserver-audit
references:
- https://attack.mitre.org/techniques/T1611
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1611/T1611.md
- https://securekubernetes.com/scenario_2_attack/
- https://twitter.com/mauilion/status/1129468485480751104
3 changes: 3 additions & 0 deletions datasets/attack_techniques/T1611/nsenter.json
Git LFS file not shown