Container Escape
Course Description
Containers are everywhere but often misconfigured. Learn to escape Docker containers and compromise Kubernetes clusters.
Learning Objectives
- Identify container misconfigurations
- Escape Docker containers
- Exploit Kubernetes clusters
- Pivot through container networks
- Compromise orchestration platforms
- Persist in containerized environments
Course Structure
Modules
Module 1: Container Fundamentals (5h)
- Docker architecture
- Container isolation
- Namespaces and cgroups
- Security mechanisms
Module 2: Docker Reconnaissance (5h)
- Container enumeration
- Image analysis
- Registry exploitation
- Secrets discovery
Module 3: Container Escape (8h)
- Privileged container escape
- Docker socket abuse
- Capabilities exploitation
- Kernel exploits
- cgroups escape
Module 4: Kubernetes Basics (5h)
- K8s architecture
- RBAC model
- Service accounts
- Network policies
Module 5: Kubernetes Attacks (8h)
- API server exploitation
- Service account abuse
- RBAC escalation
- Secrets extraction
- etcd attacks
Module 6: Advanced Techniques (5h)
- Service mesh attacks
- Admission controller bypass
- Node compromise
- Multi-cluster attacks
Module 7: Persistence (4h)
- Backdoor containers
- Malicious images
- DaemonSet persistence
- Webhook persistence
Tools
| Tool | Purpose |
|---|---|
| deepce | Container enum |
| kubectl | K8s CLI |
| kube-hunter | K8s scanning |
| Peirates | K8s exploitation |
| Trivy | Vulnerability scanning |
📄️ Overview
Docker and Kubernetes exploitation: container breakout and cluster compromise