Attacking and securing cloud identities in managed Kubernetes part 1: Amazon EKS
ID: e51d962b-6809-51cc-ae1a-d1e70abf669a
STIX ID: report--e51d962b-6809-51cc-ae1a-d1e70abf669a
Feed Name: Datadog Security Labs
This Datadog Security Labs article explains how EKS authenticates workloads and demonstrates realistic attack paths—SSRF to the EC2 instance metadata service to steal worker-node credentials, abusing node privileges to mint pod service-account tokens, and using IRSA/Pod Identity or operator roles to pivot into an AWS account. The report includes step-by-step demonstrations, discusses impact (including possible full cloud administrator compromise when workloads or operators possess broad IAM permissions), and recommends mitigations such as blocking IMDS access via network policy, enforcing IMDSv2 with a hop limit, minimizing pod IAM privileges, and using MKAT to audit clusters.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
