k8s

Containers & DevSecOps

Kubernetes RBAC Abuse and Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Containers & DevSecOps

Kubernetes Secrets and etcd Exposure

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Containers & DevSecOps

Kubernetes RBAC Attacks: Privilege Escalation from a Compromised Service Account

How attackers abuse Kubernetes RBAC roles, bindings, and service account tokens to escalate to cluster-admin, and how to defend.
Containers & DevSecOps

Attacking the Kubernetes API Server and etcd: A Practical Offensive Guide

Hands-on offensive techniques against the Kubernetes control plane: anonymous auth, etcd secret extraction, kubelet API, and exposed dashboards.
Containers & DevSecOps

Breaking and Hardening Kubernetes Pods: Pod Security Standards, OPA Gatekeeper, and Kyverno

An offensive and defensive tour of Kubernetes pod admission control: Pod Security Standards, securityContext, OPA Gatekeeper, and Kyverno.
Containers & DevSecOps

Auditing Kubernetes Clusters with kube-bench and kube-hunter

A practical guide to auditing Kubernetes for CIS benchmark gaps and exploitable misconfigs, then remediating them.