Extracting a list of running or existing pods within a containerized cluster environment. Pods are the smallest deployable units in a Kubernetes cluster and typically represent an application or workload. Enumeration of pods provides insight into the structure and state of applications running in the cluster, such as the names of pods, their namespaces, and their associated metadata.
Data Collection Measures:
/api/v1/pods.kubectl get pods.kubectl is installed using tools like auditd, Sysmon for Linux, or kernel modules.| Name | Channel |
|---|---|
| kubernetes:apiserver | list or get requests against pods, deployments, or nodes |
| ID | Name | Technique Detected |
|---|---|---|
| DET0490 | Detection Strategy for Container and Resource Discovery | T1613 |