Security

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Unit 42 describes how attackers with root access on a compromised Kubernetes node can misuse SPIFFE/SPIRE metadata to spoof and harvest identities belonging to co-located workloads. The analysis focuses on post-compromise identity abuse.

Image: Palo Alto Unit 42

Coverage 1 publisher

  1. Palo Alto Unit 42

    The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Articles stay on their publishers’ sites; each link opens the original.