Attacking Eks Gke Aks

Assess managed Kubernetes clusters on EKS, GKE, and AKS by exploiting the seams between cloud IAM and Kubernetes RBAC -- IRSA/OIDC trust abuse, Workload Identity Federation, pod-to-IMDS escalation, aws-auth ConfigMap takeover, node pool service account abuse, and AAD integration weaknesses. Use when pentesting a managed k8s cluster, reviewing RBAC in EKS/GKE/AKS, testing pod-to-cloud escalation, or assessing network policy enforcement across namespaces.

trilwu 556ec26 16.8 KB Updated

File contents

trilwu/secskills/tree/main/secskills-offense/skills/attacking-eks-gke-aks commit 556ec26a60

Frequently asked questions

npx skillmds add trilwu/attacking-eks-gke-aks