{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/pod-exec/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kubernetes"],"_cs_severities":["high"],"_cs_tags":["credential-access","kubernetes","pod-exec","cloud","threat-detection"],"_cs_type":"advisory","_cs_vendors":["Kubernetes"],"content_html":"\u003cp\u003eThis alert addresses the abuse of the Kubernetes pod exec API to perform reconnaissance and credential theft. Attackers often leverage legitimate administrative access to interactively or programmatically access sensitive files within a container. This activity frequently precedes lateral movement or privilege escalation. The scope includes access to high-value targets such as mounted service account tokens (including IRSA and Workload Identity), host configuration files (/etc/shadow, /etc/passwd), private keys, keystores, and process environment variables that may contain secrets. The detection focuses on auditing Kubernetes API server logs for exec commands that reference these sensitive paths. Defending against this requires strict RBAC controls for the exec subresource and robust monitoring of audit logs for anomalous administrative access patterns.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to a Kubernetes cluster via compromised credentials or a vulnerable workload.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates pods and containers to identify targets with sufficient privileges or sensitive mounts.\u003c/li\u003e\n\u003cli\u003eAttacker uses the 'kubectl exec' command or direct Kubernetes API calls to initiate an interactive session inside a container.\u003c/li\u003e\n\u003cli\u003eAttacker executes commands (e.g., cat, grep, ls) to probe for sensitive files or credential material in the container filesystem.\u003c/li\u003e\n\u003cli\u003eAttacker accesses high-value targets such as /var/run/secrets/kubernetes.io/serviceaccount/token or cloud-provider identity tokens.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates discovered credentials or tokens to gain higher-level access to the cluster or cloud control plane.\u003c/li\u003e\n\u003cli\u003eAttacker performs further actions such as secret dumping, RBAC modifications, or container breakout to achieve final objectives.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this technique allows an attacker to steal identity tokens, compromise service accounts, gain persistent access to the Kubernetes control plane, or escalate privileges within the cloud environment. Depending on the stolen credentials, this can lead to full cluster compromise or unauthorized access to external cloud resources (AWS, Azure, GCP).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the ESQL detection logic to the SIEM and validate against existing audit logs.\u003c/li\u003e\n\u003cli\u003eImplement RBAC controls to restrict 'exec' permissions to only necessary users and automated service identities.\u003c/li\u003e\n\u003cli\u003eReview all pods with 'hostPath' mounts or privileged security contexts as these are primary targets for credential exfiltration.\u003c/li\u003e\n\u003cli\u003eEstablish baseline monitoring for stable automation identities to reduce false positives from diagnostic or monitoring agents.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T15:47:12Z","date_published":"2026-08-24T15:47:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-k8s-pod-exec-credential-access/","summary":"Detection of Kubernetes pod exec sessions accessing sensitive host and in-cluster files used for credential theft and lateral movement.","title":"Kubernetes Pod Exec Sensitive File Access Detection","url":"https://feed.craftedsignal.io/briefs/2026-08-k8s-pod-exec-credential-access/"}],"language":"en","title":"CraftedSignal Threat Feed - Pod-Exec","version":"https://jsonfeed.org/version/1.1"}