K8s RBAC权限提升审计
原名:auditing-kubernetes-rbac-privilege-escalation
使用 kubectl auth can-i、rbac-police、kubectl-who-can 和 rakkess 等工具,在授权集群安全审查中识别过度宽松的 RBAC 角色及服务账户令牌滥用路径。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-21
- TRACE 评分
- 3 / 5
内容概览
Legal Notice: This skill is for authorized security testing and educational purposes only. Enumerating and exercising RBAC permissions affects a live cluster's access posture. Only test clusters you own or are explicitly authorized in writing to assess. Kubernetes Role-Based Access Control (RBAC, MITRE ATT&CK T1078 Valid Accounts) governs what every user and service account may do via Role/ClusterRole rules bound by RoleBinding/ClusterRoleBinding. Because workloads run with a mounted service-account token by default, an attacker who compromises one pod inherits that account's RBAC rights. Over-permissive bindings turn a single compromised pod into a cluster takeover: certain verbs and resources are "RBAC-equivalent to cluster-admin." Per the Kubernetes "RBAC Good Practices" guidance and Unit 42 research, the dangerous primitives are: - escalate on roles — grant yourself any permission, e…