How to Escape Clusters in a Managed Kubernetes Cluster?

How to Escape Clusters in a Managed Kubernetes Cluster?

Not Escaping Containers but escaping Clusters - Managed Kubernetes distributions such as Amazon EKS, Google Kubernetes Engine (GKE) and Azure Kubernetes Service (AKS) attack vectors can allow you to reach the underlying AWS Account etc. In conversation with Christophe Tafani-Dereeper & Nick Frichette, from Datadog on how this is possible in Amazon EKS and achieving potentially the same in GKE & AKS too.


Thank you to our episode sponsor Sagetap


Guest Socials: Nick's and Christophe's Linkedin (⁠⁠⁠⁠⁠⁠⁠⁠⁠Nick Frichette + Christophe Tafani-Dereeper)

Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠

If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:

- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠

- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp Questions asked: (00:00) Introduction

(04:11) A bit about Christophe

(04:37) A bit about Nick

(05:03) What is managed Kubernetes?

(06:26) Security of managed Kubernetes

(09:02) Comparison between different managed Kubernetes

(10:41) Service accounts and managed Kubernetes

(14:22) What is container escape?

(18:20) IMDSv2 for EKS

(19:51) IMDSv2 in EKS vs AKES and GKE

(22:01) Benchmark compliance for Kubernetes architecture

(24:49) Low hanging fruits for container escape

(27:17) Shared responsibility for managed Kubernetes

(29:34) Fargate for Managed Kubernetes

(32:00) Different ways to run containers

(33:37) Escaping Managed Kubernetes cluster

(38:39) Find more about this attack path

(42:38) Escalation priviledge in EKS cluster

(44:19) Reducing the Kubernetes attack service

(44:58) MKAT for Kubernetes Security

(48:23) Preventing AWS AuthConfig

(50:11) Propagation Security

(54:55) The fun section

(57:47) Resources for latest Kubernetes updates


Resources spoken about during the episode

Nick Frichette's Blog - Hacking the Cloud

Christophe Tafani-Dereeper' Blog

Corey Quinn's - 17 ways to run containers on AWS

MKAT

cloudseclist newsletter

Avsnitt(346)

Using AI to Fix Your Cloud Security Backlog beyond Visibility

Using AI to Fix Your Cloud Security Backlog beyond Visibility

You have the visibility, you see the alerts, but your security backlog is still growing faster than your team can fix it. So, are you actually getting more secure? In this episode, Snir Ben Shimol, CE...

9 Sep 202548min

Your SecOps Team Can't Save Your Cloud: A New Blueprint for Security.

Your SecOps Team Can't Save Your Cloud: A New Blueprint for Security.

The conversation around cloud security is maturing beyond simple threat detection. As the industry grapples with alert fatigue, we explore the necessary shift from a reactive to a proactive security p...

27 Aug 202547min

New Identity Blueprint for a Future with Cloud & AI

New Identity Blueprint for a Future with Cloud & AI

Identity is the root cause of over 70% of all security incidents, yet many organizations still rely on fundamentally flawed authentication methods. In this episode, Jasson Casey, CEO and co-founder of...

22 Aug 202549min

AI for SOC Automation: A Blueprint for the New world of Incident Response

AI for SOC Automation: A Blueprint for the New world of Incident Response

The nature of Security Operations is changing. As cloud environments grow in complexity and data volumes explode, traditional approaches to detection and response are proving insufficient. This episod...

8 Aug 202552min

The Truth About Agentic AI in the SOC: Reality vs. Hype

The Truth About Agentic AI in the SOC: Reality vs. Hype

What does the integration of AI into a Security Operations Center (SOC) practically look like? This episode explores the concept of the "Agentic SOC," moving beyond marketing terms to discuss its real...

7 Aug 202552min

Understanding a $10B Fraud Vector in Cloud-Native Workflows

Understanding a $10B Fraud Vector in Cloud-Native Workflows

A $10 billion fraud vector is currently exploiting a common feature in many cloud-native applications: the SMS verification flow. This isn't a traditional breach. Instead of stealing data, adversaries...

22 Juli 202544min

How BT Tackled 180 Years of Legacy to Build a Passwordless Future

How BT Tackled 180 Years of Legacy to Build a Passwordless Future

How do you modernize security in a 180-year-old company that operates critical national infrastructure? What does it look like when you discover tens or even hundreds of thousands of credentials hidde...

17 Juli 202519min

Why Security Can Be Stricter: A Zero Trust Approach to AppSec with AI

Why Security Can Be Stricter: A Zero Trust Approach to AppSec with AI

Is AI making application security easier or harder? We spoke to Amit Chita, Field CTO at Mend.io, the rise of AI agents in the Software Development Lifecycle (SDLC) presents a unique opportunity for s...

15 Juli 202545min

Populärt inom Teknik

uppgang-och-fall
market-makers
elbilsveckan
skogsforum-podcast
rss-elektrikerpodden
bilar-med-sladd
developers-mer-an-bara-kod
rss-uppgang-och-fall
rss-veckans-ai
rss-laddstationen-med-elbilen-i-sverige
rss-powerboat-sverige-podcast
rss-technokratin
bli-saker-podden
teknikveckan
hej-bruksbil
rss-fabriken-2
natets-morka-sida
gubbar-som-tjotar-om-bilar
har-vi-akt-till-mars-an
rss-snacka-om-ai