Product
high
advisory
Kubernetes Pod Exec Exploitation of Cloud Instance Metadata
2 TTPs 2 IOCsThreat actors utilize Kubernetes pod exec sessions to query cloud instance metadata endpoints for credential harvesting and unauthorized access to cloud environment resources.
AWS IMDS +2
2t
2i
high
advisory
Kubernetes Pod Exec Cloud Instance Metadata Access
2 rules 2 TTPsDetection of Kubernetes pod exec sessions accessing cloud instance metadata endpoints, indicating potential credential theft from AWS, GCP, or Azure.
AWS IMDS +2
kubernetes
cloud
credential_access
execution
2r
2t