ContainerCluster
Cluster control plane (ECS cluster/AKS/GKE/EKS).
class: Compute
Realizing resources
aws aws
| resource | scope | enumerate | required permissions |
|---|---|---|---|
aws:ecs:cluster |
regional | ecs:ListClusters |
ecs:ListClusters |
azure azure
| resource | scope | enumerate | required permissions |
|---|---|---|---|
azure:servicefabric:cluster |
global | arg:microsoft.servicefabric/clusters |
Microsoft.ServiceFabric/clusters/read |
As edge source
CanDecryptCanDeleteDataCanExfiltrateCanNetworkReachCanReachPortCanReadCredentialCanReadDataCanReadSecretCanRetrieveTokenCanWriteDataContainsCredentialContainsResourceReferenceContainsSecretExecutesAsExposedToAccountExposedToInternetExposedToTenantExposesCredentialHasPolicyLocatedInPrivateReachabilityAs edge target
AttachedToAuthenticatesToCanAdministerCanAttachIdentityCanControlCanCreateCanDeleteCanDeployCanExecuteOnCanModifyCanModifyCodeCanModifyConfigurationCanModifyPolicyCanNetworkReachCanReachPortCanReadCanReplaceCanStartCanTakeOwnershipCanTriggerCanWriteContainsContainsResourceReferenceControlsHasPermissionPrivateReachabilityExposure sites
None.
Rules that touch ContainerCluster 7
Modify an ADF Integration Runtime configuration to swap SHIR VM assignment, reconfigure managed VNet, or change IR type - enables command execution or data exfiltration via network steering.
azure
CanModifyConfigurationNode-level code execution (privileged pod, hostPID, DaemonSet exec) reaches the node IMDS and mints a token for the node system-assigned / kubelet MI.
azure
CanExecuteAsmanagedClusters/agentPools/write + assign on a target MI allows swapping the kubelet MI, binding all nodes to a more-privileged identity.
azure
CanAttachIdentitySubmit a job to an AKS cluster attached as an AML compute target; the job runs inside the AKS cluster as a Kubernetes workload, enabling lateral movement to non-AML K8s resources.
azure
CanModifyCodeModify a pool startTask/config + the pool runs as an MI => execute as that MI (via IMDS).
azure
CanExecuteAsSubmit a data-plane task + the pool runs as an MI => execute as that MI (via IMDS).
azure
CanExecuteAsThe Cloud Deploy execution SA's GKE deployment permissions (container.developer) give it CanDeploy to a GKE cluster.
gcp
CanDeploy