Skip to content

The Machine With Many Faces Post-Exploitation Identity Misus... - #405

Open
carlospolop wants to merge 1 commit into
masterfrom
update_The_Machine_With_Many_Faces_Post-Exploitation_Id_a7dba00868872d10
Open

carlospolop wants to merge 1 commit into
masterfrom
update_The_Machine_With_Many_Faces_Post-Exploitation_Id_a7dba00868872d10

Conversation

@carlospolop

Copy link
Copy Markdown
Collaborator

🤖 Automated Content Update

This PR was automatically generated by the HackTricks News Bot based on a technical blog post.

📝 Source Information

  • Blog URL: https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing
  • Blog Title: The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
  • Suggested Section: Pentesting Cloud > Kubernetes Pentesting > SPIFFE/SPIRE Workload Identity Spoofing (Cgroup-Based Workload Attestation Abuse), cross-referenced from Attacking Kubernetes from inside a Pod and Kubernetes Hardening

🎯 Content Summary

Research focus, prerequisites and impact. Published on September 10, 2026, Unit 42 describes a post-exploitation workload-identity spoofing technique against SPIFFE/SPIRE. The attacker must already have root-level or equivalent administrative control of a Kubernetes node running a SPIRE Agent. By manipulating Linux cgroup metadata used during workload attestation, the attacker can make an attacker-controlled process appear to belong to another workload colocated on the same n...

🔧 Technical Details

Cgroup-based workload selector spoofing. A root attacker on a Kubernetes node can manipulate the cgroup metadata associated with an attacker-controlled process. The SPIRE Kubernetes workload attestor reads /proc/<pid>/mountinfo or /proc/<pid>/cgroups and parses a pod UID and container ID from paths such as /kubepods.slice/.../kubepods-besteffort-pod<pod_uid>.slice/cri-containerd-<container_id>.scope. If the values are made to reference another colocated pod, the agent queries Kubernetes metadata and collects selectors for that pod, allowing the attacker process to be evaluated as the target workload. The technique abuses trust in mutable node-local metadata after root compromise rather than bypassing the cryptographic verification of an already-issued SVID.

Credential harvesting through the local Workload API. After spoofing the process metadata, the attacker requests

@carlospolop

Copy link
Copy Markdown
Collaborator Author

🔗 Additional Context

Original Blog Post: https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing

Content Categories: Based on the analysis, this content was categorized under "Pentesting Cloud > Kubernetes Pentesting > SPIFFE/SPIRE Workload Identity Spoofing (Cgroup-Based Workload Attestation Abuse), cross-referenced from Attacking Kubernetes from inside a Pod and Kubernetes Hardening".

Repository Maintenance:

  • MD Files Formatting: 815 files processed

Review Notes:

  • This content was automatically processed and may require human review for accuracy
  • Check that the placement within the repository structure is appropriate
  • Verify that all technical details are correct and up-to-date
  • All .md files have been checked for proper formatting (headers, includes, etc.)

Bot Version: HackTricks News Bot v1.0

@carlospolop

Copy link
Copy Markdown
Collaborator Author

merge

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant