T1552.007 Container API
Sub-technique of T1552 Unsecured Credentials
Adversaries may gather credentials via APIs within a containers environment. APIs in these environments, such as the Docker API and Kubernetes APIs, allow a user to remotely manage their container resources and cluster components.(Citation: Docker API)(Citation: Kubernetes API) An adversary may access the Docker API to collect logs that contain credentials to cloud, container, and various other…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Azure Kubernetes Admission Controllermediumtest · azure
- Google Cloud Kubernetes Admission Controllermediumtest · gcp
- Kubernetes Admission Controller Modificationmediumtest · kubernetes
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.