Meta tags:
Headings (most frequently used words):
unsecured, credentials, container, api, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,
Text of the page (most frequently used words):
the (30), api (26), kubernetes (22), access (16), retrieved (14), and (13), march (12), docker (11), #container (11), credentials (11), t1552 (11), att (10), all (10), for (9), 2026 (8), use (7), enterprise (7), cloud (7), techniques (6), 2022 (6), service (6), 2021 (6), account (6), unsecured (6), ics (5), mobile (5), none (5), teampcp (5), may (5), with (5), apis (5), mitre (4), resources (4), components (4), detection (4), sub (4), 2023 (4), security (4), secrets (4), server (4), such (4), version (4), are (3), reference (3), cti (3), data (3), mitigations (3), defenses (3), tactics (3), february (3), accounts (3), july (3), github (3), peirates (3), logs (3), from (3), pod (3), privileged (3), credential (3), description (3), name (3), users (3), limit (3), user (3), network (3), via (3), can (3), 007 (3), corporation (2), preferences (2), policy (2), domains (2), campaigns (2), software (2), groups (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), role (2), based (2), control (2), agency (2), infrastructure (2), april (2), managed (2), azure (2), native (2), authors (2), supply (2), chain (2), attack (2), january (2), chen (2), direct (2), calls (2), where (2), adversaries (2), get (2), analytic (2), authentication (2), restrict (2), least (2), privileges (2), required (2), permissions (2), group (2), management (2), consider (2), disabling (2), remote (2), over (2), environments (2), that (2), query (2), stealer (2), keys (2), mini (2), shai (2), hulud (2), october (2), containers (2), technique (2), adversary (2), other (2), environment (2), these (2), cluster (2), history (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, website, changelog, privacy, terms, contact, reset, filters, good, practices, national, cybersecurity, hardening, guide, configure, pods, microsoft, aks, active, directory, integration, overview, controlling, protect, daemon, socket, unit, weaponizing, protectors, multi, stage, mccarthy, haughom, read, kics, action, compromised, strikes, again, inguardians, hunt, how, python, toolkit, survives, takedown, firescale, victim, own, 2020, attacker, daemons, revealed, engine, references, correlates, anomalous, requests, observes, unauthorized, endpoints, identifies, behavioral, patterns, escalate, basic, interaction, exposing, sensitive, material, kubectl, an0571, detect, abuse, det0198, strategy, enforce, when, using, avoid, giving, wildcard, adding, rather, than, specific, namespaces, clusterrolebindings, rolebindings, system, masters, m1018, principle, privilege, example, not, altogether, m1026, deny, internal, systems, through, proxies, gateways, firewalls, segmentation, m1030, communications, secured, channels, local, unix, sockets, ssh, require, secure, port, communicate, tls, unauthenticated, clusters, deployed, platform, features, ranges, permitted, possible, enabling, just, time, jit, place, additional, restrictions, resource, m1035, mitigation, s9041, s0683, has, gathered, stored, orchestrators, s9043, procedure, examples, live, permalink, 2025, last, modified, created, center, threat, informed, defense, ctid, jay, palo, alto, networks, yossi, weizman, defender, research, team, contributors, platforms, tactic, collect, contain, various, sufficient, also, retrieve, include, those, needed, gather, within, allow, remotely, manage, their, chat, messages, 008, 006, instance, metadata, 005, private, 004, shell, 003, registry, 002, files, 001, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, engage, tools, advisory, council, learn, more, about, started, detections,
Text of the page (random words):
unsecured credentials container api sub technique t1552 007 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise unsecured credentials container api unsecured credentials container api other sub techniques of unsecured credentials 8 id name t1552 001 credentials in files t1552 002 credentials in registry t1552 003 shell history t1552 004 private keys t1552 005 cloud instance metadata api t1552 006 group policy preferences t1552 007 container api t1552 008 chat messages adversaries may gather credentials via apis within a containers environment apis in these environments such as the docker api and kubernetes apis allow a user to remotely manage their container resources and cluster components 1 2 an adversary may access the docker api to collect logs that contain credentials to cloud container and various other resources in the environment 3 an adversary with sufficient permissions such as via a pod s service account may also use the kubernetes api to retrieve credentials from the kubernetes api server these credentials may include those needed for docker api authentication or secrets from kubernetes cluster components id t1552 007 sub technique of t1552 ⓘ tactic credential access ⓘ platforms containers contributors center for threat informed defense ctid jay chen palo alto networks yossi weizman azure defender research team version 1 2 created 31 march 2021 last modified 24 october 2025 version permalink live version procedure examples id name description s9043 mini shai hulud mini shai hulud has gathered unsecured api keys stored in container orchestrators 4 s0683 peirates peirates can query the kubernetes api for secrets 5 s9041 teampcp cloud stealer teampcp cloud stealer can query the kubernetes api for credentials 6 7 mitigations id mitigation description m1035 limit access to resource over network limit communications with the container service to managed and secured channels such as local unix sockets or remote access via ssh require secure port access to communicate with the apis over tls by disabling unauthenticated access to the docker api and kubernetes api server 8 9 in kubernetes clusters deployed in cloud environments use native cloud platform features to restrict the ip ranges that are permitted to access to api server 10 where possible consider enabling just in time jit access to the kubernetes api to place additional restrictions on access 11 m1030 network segmentation deny direct remote access to internal systems through the use of network proxies gateways and firewalls m1026 privileged account management use the principle of least privilege for privileged accounts such as the service account in kubernetes for example if a pod is not required to access the kubernetes api consider disabling the service account altogether 12 m1018 user account management enforce authentication and role based access control on the container api to restrict users to the least privileges required 13 when using kubernetes avoid giving users wildcard permissions or adding users to the system masters group and use rolebindings rather than clusterrolebindings to limit user privileges to specific namespaces 14 detection strategy id name analytic id analytic description det0198 detect abuse of container apis for credential access an0571 detection correlates anomalous docker or kubernetes api requests with access to logs secrets or service accounts observes unauthorized use of docker logs kubectl get secrets or direct api calls to kubernetes api server endpoints identifies behavioral patterns where adversaries escalate from basic pod container interaction to privileged api calls exposing sensitive credential material references docker n d docker engine api v1 41 reference retrieved march 31 2021 the kubernetes authors n d the kubernetes api retrieved march 29 2021 chen j 2020 january 29 attacker s tactics and techniques in unsecured docker daemons revealed retrieved march 31 2021 hunt io 2026 may 14 how teampcp s python toolkit survives a c2 takedown firescale github and the victim s own account retrieved july 16 2026 inguardians 2022 january 5 peirates github retrieved february 8 2022 mccarthy r haughom j read b 2026 march 23 kics github action compromised teampcp strikes again in supply chain attack retrieved july 1 2026 unit 42 2026 march 31 weaponizing the protectors teampcp s multi stage supply chain attack on security infrastructure retrieved july 1 2026 docker n d protect the docker daemon socket retrieved march 29 2021 the kubernetes authors n d controlling access to the kubernetes api retrieved march 29 2021 kubernetes n d overview of cloud native security retrieved march 8 2023 microsoft 2023 february 27 aks managed azure active directory integration retrieved march 8 2023 kubernetes 2022 february 26 configure service accounts for pods retrieved april 1 2022 national security agency cybersecurity and infrastructure security agency 2022 march kubernetes hardening guide retrieved april 1 2022 kubernetes n d role based access control good practices retrieved march 8 2023 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|