Threat hunts for Kubernetes
26 hunts covering Kubernetes, each with a hypothesis, the queries that test it and what the hunt cannot see.
26 hunts
-
medium Part 2 of 2Research by Cisco Talos
Unauthorized RMM and Ransomware Precursors
An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
medium Part 1 of 2Research by Cisco Talos
Cloud Identity and AI Agent Anomalies
An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.
3 query2 analytic2 checkpoint1 action2 taskcredential access · discovery · impact -
highResearch by Unit 42
Kubernetes Operator RBAC Abuse and Secret Theft
A vulnerable or outdated Kubernetes operator is running with excessive ClusterRole permissions, allowing an attacker to exfiltrate cluster-wide secrets or establish unauthorized AI agent bridges to external endpoints.
3 query1 analytic1 checkpoint2 taskCVE-2026-6389 -
high Part 2 of 2Research by Microsoft
Storm-3068 Build Pipeline Execution and Tunneling
An adversary has modified build pipelines to execute malicious code on agents, deploying RMM tools and establishing tunnels to exfiltrate Kubernetes credentials.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 2Research by Microsoft
Cloud Identity Takeover and DevOps Enumeration
An adversary hijacked a cloud identity using self-service password reset to perform automated discovery across Azure DevOps repositories and harvest Kubernetes configuration files.
4 query2 analytic2 checkpoint1 action3 taskcommand and control · credential access · discovery -
high Part 2 of 2Research by The DFIR Report
Bissa Scanner C2 and S3 Exfiltration
An attacker is using Telegram for command-and-control alerts and Filebase S3 for data exfiltration after harvesting secrets from vulnerable application servers.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-9501 -
high Part 1 of 2Research by The DFIR Report
Bissa Scanner Mass Exploitation and Credential Harvesting
An attacker is using the Bissa scanner to exploit unauthenticated vulnerabilities in Next.js or WordPress, then harvesting sensitive credentials from .env files and cloud metadata.
3 query2 analytic2 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-9501 -
mediumResearch by Elastic Security Labs
Vulnerable Driver Exploitation and Kernel Escalation
An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.
4 query2 analytic2 checkpoint1 action2 taskexecution · initial access · privilege escalation -
medium Part 2 of 2Research by Microsoft
Cloud Workload Identity and Network Triage
An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
medium Part 1 of 2Research by Microsoft
Cloud Workload Runtime and Exploitation Behavior
An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.
3 query2 analytic2 checkpoint1 action3 taskcommand and control · credential access · defense evasion -
highResearch by Elastic Security Labs
Kubernetes Service Account Abuse and Escape
An intruder has harvested a service account token from a compromised pod and is using it to deploy a privileged pod for container escape, bypassing standard runtime process detection.
4 query2 analytic1 checkpoint1 action2 taskcredential access · discovery · execution -
highResearch by Unit 42
SPIFFE/SPIRE Workload Identity Spoofing
An attacker with root access on a Kubernetes node is spoofing cgroup metadata to trick the SPIRE agent into issuing identities belonging to co-located workloads for unauthorized service impersonation.
4 query2 analytic1 checkpoint1 action3 taskcommand and control · credential access · defense evasion -
medium Part 2 of 2Research by Unit 42
Anomalous Cloud Identity Behavior
An adversary has compromised an administrative cloud identity and is accessing the environment through multi-hop proxies or Tor to perform discovery and initial access.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · discovery · execution -
medium Part 1 of 2Research by Unit 42
Public app exploitation and cloud identity drift
An adversary has exploited a public-facing application on a cloud instance to obtain its identity, which is now being used for activity that deviates from the host's established behavioral profile.
5 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
highResearch by Elastic Security Labs
Obfuscated Identity and Host Access
An adversary is using multi-hop proxies or tunnels to mask their origin during authentication to cloud identity providers, subsequently using that access to reach internal hosts and execute local commands.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Unit 42
ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation
An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Unit 42
ChainDrop: NPM Worm Endpoint and CI Runner Activity
An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 3 of 3Research by Datadog Security Labs
Shai-Hulud: Exfiltration and Deadman Switch
An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by Datadog Security Labs
Shai-Hulud Secret Harvesting and Discovery
An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by Datadog Security Labs
Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap
The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
mediumResearch by Elastic Security Labs
Suspicious ingress tool transfer via native utilities
An adversary is using native Linux or macOS utilities like curl or wget to download malicious payloads from external infrastructure, hiding their activity within the high volume of legitimate cloud automation.
3 query1 analytic1 checkpoint1 action2 taskcommand and control -
high Part 2 of 2Research by Cisco Talos
VoidLink Lateral Scanning and Mesh C2
An intruder is using a VoidLink implant to perform automated internal reconnaissance and establish a peer-to-peer mesh command-and-control network between compromised Linux servers.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by Cisco Talos
VoidLink: Exploitation and Kernel-Level Implant Deployment
An adversary has exploited a Java-based Apache Dubbo service to deploy a ZigLang-based VoidLink implant and maintained stealth using an unsigned kernel-level rootkit.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 2 of 2Research by Elastic Security Labs
CHAINDROP: C2 Discovery and Worm Propagation
An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Elastic Security Labs
CHAINDROP: Host-Based Node.js Worm Execution and Harvesting
An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Wiz
TeamPCP Credential Validation and Discovery
An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.
4 query1 analytic1 checkpoint1 action2 taskdiscovery · execution · exfiltration