Adversaries may abuse a container administration service to execute commands within a container. A container administration service such as the Docker daemon, the Kubernetes API server, or the kubelet may allow remote management of containers within an environment.(Citation: Docker Daemon CLI)(Citation: Kubernetes API)(Citation: Kubernetes Kubelet) In Docker, adversaries may specify an entrypoint during container deployment that executes a script or command, or they may use a command such as docker exec to execute a command within a running container.(Citation: Docker Entrypoint)(Citation: Docker Exec) In Kubernetes, if an adversary has sufficient permissions, they may gain remote execution in a container in the cluster via interaction with the Kubernetes API server, the kubelet, or by running a command such as kubectl exec.(Citation: Kubectl Exec Get Shell)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by User Account Management
is blocked by Detection Strategy for Container Administration Command Abuse
is blocked by Privileged Account Management
is blocked by Disable or Remove Feature or Program
is blocked by Limit Access to Resource Over Network
is blocked by Execution Prevention
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Separation of Duties (SoD)
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Remote Access
is blocked by Input Data Validation
Impressum German English