can-i gtfo?

Kubernetes RBAC Abuse Collection

View on GitHub

update pods/ephemeralcontainers

Abuses

Container Escape

Update ephemeral containers with host access capabilities to escape container boundaries

# Update pod with ephemeral container that has host network access
# Update pod with ephemeral container that mounts host filesystem

Lateral Movement

Update ephemeral containers on other nodes with host access capabilities to escape container boundaries

# Update pod with ephemeral container that has host network access
# Update pod with ephemeral container that mounts host filesystem