Adversaries may gather credentials via APIs within a containers environment. APIs in these environments, such as the Docker API and Kubernetes APIs, allow a user to remotely manage their container resources and cluster components.(Citation: Docker API)(Citation: Kubernetes API) An adversary may access the Docker API to collect logs that contain credentials to cloud, container, and various other resources in the environment.(Citation: Unit 42 Unsecured Docker Daemons) An adversary with sufficient permissions, such as via a pod's service account, may also use the Kubernetes API to retrieve credentials from the Kubernetes API server. These credentials may include those needed for Docker API authentication or secrets from Kubernetes cluster components.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Detect Abuse of Container APIs for Credential Access
is blocked by Privileged Account Management
is blocked by Limit Access to Resource Over Network
is blocked by Network Segmentation
is blocked by User Account Management
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Transmission Confidentiality
is blocked by Transmission Integrity
is blocked by Data Mining Protection
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Cross Domain Solution (CDS)
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Remote Access
Impressum Deutsch Englisch