Defeating Kubernetes Privilege Escalation: A Cloud Detection & Response Case Study
ID: c46ab3f5-6348-5269-ab46-37d81ea28a74
STIX ID: report--c46ab3f5-6348-5269-ab46-37d81ea28a74
Feed Name: Wiz Blog
This case study describes an attack where a newly published RCE in an open-source application on an EC2 host was exploited; attackers used the host's Instance Metadata Service to assume the EC2 instance IAM role (which was used by an EKS pod) and performed reconnaissance toward the AWS control plane. Detection relied on environment-aware heuristics noting irregular IAM role usage and corroborating CloudTrail, VPC Flow, and OS forensic logs; the report stresses rapid contextualized response, vulnerability management, and network/application segmentation to reduce such cloud escalation risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
