KubeHound: Identifying attack paths in Kubernetes clusters
ID: 4ae89753-3409-5941-97ae-92cd86781c68
STIX ID: report--4ae89753-3409-5941-97ae-92cd86781c68
Feed Name: Datadog Security Labs
This report introduces KubeHound, an open-source tool by Datadog that builds a graph of Kubernetes entities and attack edges to visualize and query attack paths, shifting defenders from list-based to graph-based security. It shows how to identify critical paths from exposed endpoints to high-privilege roles, quantify remediation impact (e.g., reducing TOKEN_BRUTEFORCE-based paths), scope investigations, and track risk metrics, while detailing its Gremlin-based DSL, deployment workflow, and modular architecture.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
