Technique.View on attack.mitre.org
Adversaries may attempt to discover containers and other resources that are available within a containers environment. Other resources may include images, deployments, pods, nodes, and other information such as the status of a cluster.
These resources can be viewed within web applications such as the Kubernetes dashboard or can be queried via the Docker and Kubernetes APIs. In Docker, logs may leak information about the environment, such as the environment’s configuration, which services are available, and what cloud provider the victim may be utilizing. The discovery of these resources may inform an adversary’s next steps in the environment, such as how to perform lateral movement and which methods to utilize for execution.
Rules on DetectionCode tagged with T1613.
| Rule | Level | Log source |
|---|---|---|
| Kubernetes Potential Enumeration Activity | medium | kubernetes / NULL |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupTeamTNT | TeamTNT has checked for running containers with |
| Used by | Procedure example |
|---|---|
| MalwareCanisterWorm | CanisterWorm has performed environment fingerprinting to identify Kubernetes clusters. CanisterWorm has also searched for Kubernetes pods using the command ` os.path.exists("/var/run/secrets/kubernetes.io/serviceaccount") or "KUBERNETES_SERVICE_HOST" in os.environ `. |
| MalwareHildegard | Hildegard has used masscan to search for kubelets and the kubelet API for additional running containers. |
| ToolPeirates | Peirates can enumerate Kubernetes pods in a given namespace. |
| MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify Docker and Kubernetes environments for credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.