logo

Intro to forensics in the cloud: A container was compromised. What’s next?

ID: 0bc4ca3d-c010-5ef1-a688-b08e0e7afb08

STIX ID: report--0bc4ca3d-c010-5ef1-a688-b08e0e7afb08

Feed Name: Wiz Blog

Threat Score
72/100

Date Published: 2023-04-06

Date Updated: 2026-05-01

...
...

This report is a cloud-forensics primer that walks through a simulated breach where weak WordPress credentials and an uploaded web shell led to a reverse shell, container escape via a privileged pod and docker.sock, creation of a privileged backdoor container for persistence, lateral movement to a data-fetcher pod, and exfiltration of sensitive S3 data. It emphasizes preparation and comprehensive logging (cloud provider audit logs, VPC flow logs, Kubernetes audit logs, workload snapshots, and runtime events) and illustrates investigation steps and prevention lessons.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.