Peirates - Kubernetes 渗透测试工具
Peirates, a Kubernetes penetration tool, enables an attacker to escalate privilege and pivot through a Kubernetes cluster. It automates known techniques to steal and collect service account tokens, secrets, obtain further code execution, and gain control of the cluster.
You run Peirates from a container running on Kubernetes or from a Kubernetes node, outside the container.
Yes, it absolutely does. Talk to your lawyer and the cluster owners before using this tool in a Kubernetes cluster.
InGuardians' CTO Jay Beale first conceived of Peirates and put together a group of InGuardians developers to create it with him, including Faith Alderson, Adam Crompton and Dave Mayer. Faith convinced us to all learn Golang, so she could implement the tool's use of the kubectl library from the Kubernetes project. Adam persuaded the group to use a highly-interactive user interface. Dave brought contagious enthusiasm. Together, these four developers implemented attacks and began releasing this tool that we use on our penetration tests.
Other contributors have helped as well - see GitHub to see more, but please also review credits.md.
Yes, we absolutely do. Submit a pull request and/or reach out to [email protected].
Peirates is released under the GPLv2 license.
If you just want the peirates binary to start attacking things, grab the latest release from the releases page.
For command behavior, prerequisites, side effects, cleanup, and troubleshooting, see the main menu command reference.
You can find a useful alpine-peirates container image on Docker Hub, with a version number tag that tracks the Peirates version.
For example, for alpine-peirates:v1.1.32, which contains peirates version v1.1.32, run:
docker pull bustakube/alpine-peirates:v1.1.32
However, if you want to build from source, read on!
make build-amd64
make build-arm
make build-arm64
make build-86
The default build target generates a statically linked Linux AMD64 executable
named peirates in the repository root. You can also invoke it explicitly with
make build.
make build
To build another single architecture without creating a distribution archive, use a target like so:
make build-amd64
make build-arm
make build-arm64
make build-x86
The output file's name uses BINARY and defaults to peirates in the repository root.
Build compressed Linux distributions for AMD64, ARM, ARM64, and 386:
make dist
Distribution archives contain statically linked binaries and are written to
scripts/. Set DIST_COMPRESS=no to keep unpacked binaries or
DIST_ARCHES=amd64 to build a subset of architectures. Individual targets such
as make dist-arm64 are also available.
FEATURE REQUEST/BUG: curl doesn't show headers returned, which would include authn cookies
Ability to specify a directory for stealing Service Account Token
Installation errors
Add nsenter functionality.
Feature request: move temp files to /dev/shm
Strip down the final binary
Feature request: mount drive in privileged pod to write crontab or systemd file
module declares its path as: github.com/google/gnostic but was required as: github.com/googleapis/gnostic
test harness
Enable Mend or equivalent to manage libs