工具项目
The outline of the project is loading
小迪安全知识库
-
+
home
针对K8s综合利用工具
针对K8s综合利用工具
# K8sPenTool 项目地址:https://github.com/trymonoly/K8sPenTool/ [](https://github.com/trymonoly/K8sPenTool/#k8spentool) > Kubernetes 综合渗透测试工具 — 一站式 K8s 安全评估 GUI 平台 **作者: T3Y** [](https://github.com/trymonoly/K8sPenTool/blob/main/img/Snipaste_2026-04-26_18-55-40.jpg) | 模块 | 说明 | |---------------|--------------------------------------------------------------------| | 🔍 信息搜集 | 容器环境辨别、特权检测、Capabilities 解码、K8s 端口扫描、SA Token 枚举 | | 🚪 初始访问 | APIServer 未授权检测、Kubelet API 利用、Etcd 未授权、Dashboard 检测、Kubeconfig 解析 | | ⚡ 命令执行 | APIServer/Kubelet exec、后门 Pod 部署、反弹 Shell 生成、RBAC 权限检查 | | 🔒 权限维持 | Admin SA 创建、CronJob/DaemonSet 持久化、影子 Kubeconfig、宿主机持久化 | | 🔓 权限提升 | 特权容器逃逸、挂载逃逸(procfs/docker.sock/disk)、内核漏洞利用 | | 🌐 横向移动 | Secret 凭证窃取、集群内网探测、污点容忍横向扩展 | | 🛠 kubectl 操作 | 快捷 kubectl 命令、自定义命令执行、后门 Pod 管理 |
xiaodi
Aug. 5, 2026, 3:08 p.m.
42
0 comment
Forward
Favorites
Last
Next
Scan the QR Code
Copy link
Scan the QR code to share.
Copy link
share
link
type
password
Update password
Validity period
Markdown file
Word document
PDF document
PDF document (print)