Kubernetes API limitations in finding non-standard pods and containers
ID: 853965c6-0209-549c-b34a-6a41039b48f7
STIX ID: report--853965c6-0209-549c-b34a-6a41039b48f7
Feed Name: Wiz Blog
This report examines visibility gaps in Kubernetes for non-standard pods and containers—static, mirror, init, pause, and ephemeral—highlighting how adversaries can exploit these blind spots for stealth and persistence. It details how these objects are created, where and how they can (or cannot) be observed via the Kubernetes API, and provides guidance and example commands for detection and monitoring, emphasizing the need for complementary runtime visibility beyond the API.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
