Peirates

S0683

Tool.View on attack.mitre.org

About this tool

Peirates is a post-exploitation Kubernetes exploitation framework with a focus on gathering service account tokens for lateral movement and privilege escalation. The tool is written in GoLang and publicly available on GitHub.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1046
Network Service Discovery

Peirates can initiate a port scan against a given IP address.

T1078.004
Cloud Accounts

Peirates can use stolen service account tokens to perform its operations.

T1528
Steal Application Access Token

Peirates gathers Kubernetes service account tokens using a variety of techniques.

T1530
Data from Cloud Storage

Peirates can dump the contents of AWS S3 buckets. It can also retrieve service account tokens from kOps buckets in Google Cloud Storage or S3.

T1550.001
Application Access Token

Peirates can use stolen service account tokens to perform its operations. It also enables adversaries to switch between valid service accounts.

T1552.005
Cloud Instance Metadata API

Peirates can query the query AWS and GCP metadata APIs for secrets.

T1552.007
Container API

Peirates can query the Kubernetes API for secrets.

T1609
Container Administration Command

Peirates can use `kubectl` or the Kubernetes API to run commands.

T1610
Deploy Container

Peirates can deploy a pod that mounts its node’s root file system, then execute a command to create a reverse shell on the node.

T1611
Escape to Host

Peirates can gain a reverse shell on a host node by mounting the Kubernetes hostPath.

T1613
Container and Resource Discovery

Peirates can enumerate Kubernetes pods in a given namespace.

T1619
Cloud Storage Object Discovery

Peirates can list AWS S3 buckets.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Peirates GitHub Open source
    InGuardians. (2022, January 5). Peirates GitHub. Retrieved February 8, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.