Full Report
We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray Your Security Posture appeared first on Unit 42.
Analysis Summary
# Tool/Technique: OperTraitor
## Overview
OperTraitor is an open-source security auditing tool designed to analyze Kubernetes Operators for privilege escalation risks and excessive Role-Based Access Control (RBAC) permissions. It addresses the "non-human identity" security gap where Operators—software extensions intended to manage complex applications—are granted over-privileged permissions that can be exploited by attackers to achieve cluster-wide compromise.
## Technical Details
- **Type:** Security Auditing Tool / Post-Exploitation Analysis Framework
- **Platform:** Kubernetes (K8s) Environments
- **Capabilities:** RBAC analysis, static manifest scanning, privilege escalation path identification, and automated security auditing.
- **First Seen:** October 2024 (Released by Unit 42)
## MITRE ATT&CK Mapping
- **[TA0004 - Privilege Escalation]**
- [T1611 - Escape to Host]
- [T1548 - Abuse Elevation Control Mechanism]
- **[TA0006 - Credential Access]**
- [T1555.005 - Password Stores: Cloud Initialized Credentials]
- **[TA0007 - Discovery]**
- [T1613 - Container and Resource Discovery]
- [T1083 - File and Directory Discovery]
## Functionality
### Core Capabilities
- **Static Analysis:** Scans YAML manifests and Helm charts of Operators to identify excessive `verbs` (e.g., `*`, `create`, `patch`) and `resources`.
- **RBAC Mapping:** Visualizes the relationship between ServiceAccounts, Roles, and ClusterRoles to find hidden permission chains.
- **Risk Scoring:** Evaluates the potential impact if a specific Operator’s identity is compromised.
### Advanced Features
- **Escalation Path Detection:** Specifically searches for permissions that allow an Operator to create new pods with elevated privileges or access sensitive secrets.
- **Cross-Namespace Analysis:** Identifies ClusterRoles that may inadvertently grant permissions across the entire cluster rather than a specific namespace.
## Indicators of Compromise
*Note: As OperTraitor is a defensive/auditing tool, these indicators refer to the behaviors of an exploited Operator or a malicious actor mimicking one.*
- **File Names:** `opertraitor` (binary/repository name)
- **Behavioral Indicators:**
- Unusually high volume of `list`, `watch`, or `get` requests for `Secrets` or `ConfigMaps` from a single ServiceAccount.
- Creation of pods with `hostPath` mounts or `privileged: true` by a non-admin ServiceAccount.
- Modification of RBAC policies (`ClusterRoleBinding` changes) by a non-human identity.
## Associated Threat Actors
- **N/A:** This is a security tool. However, the techniques it identifies (RBAC abuse) are commonly leveraged by sophisticated actors targeting cloud-native environments to move laterally from a single pod to the underlying node or the entire cluster.
## Detection Methods
- **Behavioral Detection:** Monitor Kubernetes Audit Logs for the `impersonate` verb or unexpected `patch` operations on security-sensitive resources by Operator ServiceAccounts.
- **Policy Engine Rules:** Use OPA (Open Policy Agent) or Kyverno to detect and block the deployment of Operators that request high-risk permissions (like `*.core` access).
## Mitigation Strategies
- **Principle of Least Privilege (PoLP):** Review Operator permissions and remove administrative "wildcard" (`*`) verbs.
- **Namespace Isolation:** Restrict Operators to specific namespaces using `RoleBindings` instead of `ClusterRoleBindings` whenever possible.
- **Regular Auditing:** Integrate OperTraitor or similar RBAC visualizers into the CI/CD pipeline to catch over-privileged manifests before deployment.
- **Credential Rotation:** Regularly rotate ServiceAccount tokens and move toward short-lived identities.
## Related Tools/Techniques
- **RBAC-tool:** A Kubernetes plugin for visualizing RBAC.
- **KubiScan:** A tool for scanning Kubernetes clusters for risky permissions.
- **Peirates:** A Kubernetes penetration testing tool.
- **Bad Pods:** A collection of manifests used to demonstrate privilege escalation via pod creation.