agentsclimarketplace

Container k8s escape

Skill hypnguyen1209/offensive-claude/skills/container-k8s-escape

Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

Install
npx -y skills add hypnguyen1209/offensive-claude --skill container-k8s-escape

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Use when breaking out of a container or escalating inside Kubernetes — runc/BuildKit CVEs, privileged/capability/cgroup misconfig escapes, NVIDIA GPU toolkit escape, K8s RBAC abuse, kubelet RCE, ingress/admission-controller RCE, node-to-cluster pivot

SKILL.md

9.9 KB, as published. Nobody here has run it

Container Breakout & Kubernetes Escape

When to Activate

  • You have code execution inside a container/pod and want to break out to the host node
  • Auditing a Kubernetes cluster for RBAC privilege-escalation and lateral-movement paths
  • Assessing runc/containerd/BuildKit/Docker runtime versions against known escape CVEs
  • A pod is privileged, has dangerous capabilities, hostPath/hostPID/hostNetwork, or a mounted docker.sock
  • Attacking GPU/AI workloads using the NVIDIA Container Toolkit
  • Testing ingress-nginx / admission-controller exposure for unauthenticated RCE
  • Post-escape: pivoting from one node to full cluster takeover (kubelet, SA tokens, etcd, cloud IMDS)
  • Building Falco/Sigma detections for container-escape behavior (defensive validation)

Technique Map

TechniqueATT&CKCWEReferenceScript
runc working-dir fd leak escape (Leaky Vessels, CVE-2024-21626)T1611CWE-403references/runtime-cve-escapes.mdscripts/runc_cwd_escape.py
runc masked-path / /dev/null symlink escape (CVE-2025-31133)T1611CWE-367references/runtime-cve-escapes.mdscripts/runc_cwd_escape.py
runc /dev/console bind-mount + LSM bypass (CVE-2025-52565/52881)T1611CWE-363references/runtime-cve-escapes.mdscripts/escape_enum.sh
BuildKit cache/teardown symlink escape (CVE-2024-23651/52/53)T1611CWE-59references/runtime-cve-escapes.mdscripts/escape_enum.sh
Privileged / CAP_SYS_ADMIN cgroup release_agent escapeT1611CWE-269references/privileged-misconfig-escape.mdscripts/release_agent_escape.sh
core_pattern host-side code exec on crashT1611CWE-269references/privileged-misconfig-escape.mdscripts/release_agent_escape.sh
hostPID + nsenter into PID 1 namespaceT1611CWE-668references/privileged-misconfig-escape.mdscripts/escape_enum.sh
Mounted docker.sock / containerd.sock host takeoverT1610CWE-668references/privileged-misconfig-escape.mdscripts/escape_enum.sh
hostPath / mount → write host filesystemT1611CWE-22references/privileged-misconfig-escape.mdscripts/escape_enum.sh
NVIDIAScape LD_PRELOAD OCI-hook escape (CVE-2025-23266)T1611CWE-426references/nvidia-gpu-escape.mdscripts/nvidiascape_build.sh
NVIDIA CT TOCTOU mount escape (CVE-2024-0132 / CVE-2025-23359)T1611CWE-367references/nvidia-gpu-escape.mdscripts/nvidiascape_build.sh
K8s RBAC privesc (verb/wildcard/escalate, SA token theft)T1078.001CWE-269references/k8s-rbac-escalation.mdscripts/k8s_rbac_audit.py
nodes/proxy GET → kubelet WebSocket exec RCET1609CWE-863references/k8s-rbac-escalation.mdscripts/kubelet_exec.py
Anonymous/authed kubelet API exec on :10250T1609CWE-306references/k8s-rbac-escalation.mdscripts/kubelet_exec.py
IngressNightmare unauth RCE (CVE-2025-1974 + annotation chain)T1190CWE-94references/ingress-admission-attacks.mdscripts/escape_enum.sh
Node → cluster pivot (etcd, IMDS, SA-token harvest)T1613CWE-552references/node-host-pivot.mdscripts/escape_enum.sh

Quick Start

# 0. Enumerate the container/pod context: caps, mounts, sockets, runtime versions, K8s creds
bash scripts/escape_enum.sh                 # run INSIDE the target container

# 1. Runtime-CVE path: detect vulnerable runc/BuildKit and run the cwd-fd escape (CVE-2024-21626)
python3 scripts/runc_cwd_escape.py --probe                       # try fd 7,8,9 -> host /
python3 scripts/runc_cwd_escape.py --cmd 'id; cat /etc/shadow'   # via docker -w or k8s revshell

# 2. Misconfig path: privileged / CAP_SYS_ADMIN -> cgroup release_agent host code exec
bash scripts/release_agent_escape.sh -c 'id > /tmp/escape_out'   # reads host PID list / runs cmd

# 3. GPU path: build a malicious image for NVIDIAScape (CVE-2025-23266)
bash scripts/nvidiascape_build.sh --cmd 'id; cat /etc/shadow' --tag evil-gpu:latest

# 4. K8s RBAC: audit who can escalate / reach the kubelet (needs a kubeconfig or in-pod SA token)
python3 scripts/k8s_rbac_audit.py --kubeconfig ~/.kube/config --dangerous

# 5. nodes/proxy or open kubelet -> exec into any pod on the node
python3 scripts/kubelet_exec.py --node 10.0.0.5 --pod kube-system/etcd-master \
        --container etcd --cmd 'cat /var/lib/etcd/...' --token "$SA_TOKEN"

Recommended tooling: deepce / cdk / amicontained (in-container recon), peirates (K8s pivot), kube-hunter (cluster scan), kubeletctl (kubelet API), crictl (post-escape node control), falco (defensive validation of every technique below).

OPSEC & Detection (summary)

TechniqueTelemetry / IOCDetection (Sigma/EDR/Falco)OPSEC note
runc cwd-fd escape (CVE-2024-21626)container process cwd under /proc/self/fd/N; getcwd ENOENT errors; host-path access from pid1Falco Container Drift/unexpected host-fs read; alert on runtime < runc 1.1.12No new files needed; works via -w/cwd only — very quiet, but lands on real host fs
runc 2025 trio (masked-path/console)symlink swap of /dev/null or /dev/pts/N; RW open of /proc/sysrq-trigger/core_patternFalco "Write below /proc/sys"/sysrq; mount race anomaliesSymlink swap is a timing race; on failure may crash host (sysrq) — loud
release_agent / core_patternmount of cgroup/cgroup2; write to */release_agent or /proc/sys/kernel/core_patternFalco Detect release_agent File Container Escapes; Sigma on write to core_patternRequires CAP_SYS_ADMIN+mount; release_agent is cgroup-v1 only
nsenter / hostPIDnsenter --target 1; process entering host mount/pid nsFalco "nsenter" / proc.name=nsenter in container; ATT&CK T1611hostPID is visible in pod spec; nsenter is a strong IOC
docker.sock abuse/var/run/docker.sock mounted; curl --unix-socket create privileged containerFalco "Docker socket access by unexpected proc"; new privileged container eventSpawns a new privileged container — visible to docker/containerd events
NVIDIAScape (CVE-2025-23266)image ENV LD_PRELOAD=/proc/self/cwd/*.so; nvidia hook loads .so from container fsFalco shared-lib load by nvidia-ctk/hook from container pathNeeds only image push + run; no kernel bug — image scan catches the ENV
nodes/proxy → kubelet execWebSocket GET to kubelet /exec//run on :10250; no API-server audit entryRuntime/L7 only — invisible to API audit & GuardDuty; monitor kubelet access logBypasses API-server audit & admission entirely — extremely stealthy
K8s RBAC privesc / SA-token theftread of /var/run/secrets/.../token; can-i probes; bind to cluster-adminAPI audit create rolebindings/escalate; Falco Read SA tokenkubectl auth can-i probing is logged at API server
IngressNightmare (CVE-2025-1974)AdmissionReview with injected NGINX directive; .so loaded from /proc/<pid>/fdSysdig/Falco "IngressNightmare"; shared-lib load from /proc in nginxCode runs during nginx -t validation; controller SA grabs all-namespace secrets

Deep Dives

  • references/runtime-cve-escapes.md — runc CVE-2024-21626 (working-dir fd leak), the Nov-2025 runc trio (CVE-2025-31133/52565/52881 masked-path & /dev/console), and the BuildKit Leaky Vessels CVEs, with full PoCs and version matrices.
  • references/privileged-misconfig-escape.md — --privileged/capability escapes: cgroup-v1 release_agent, core_pattern, hostPID+nsenter, mounted docker/containerd sockets, and hostPath// mounts, with complete scripts.
  • references/nvidia-gpu-escape.md — NVIDIAScape (CVE-2025-23266 LD_PRELOAD OCI-hook) and the CVE-2024-0132 / CVE-2025-23359 TOCTOU mount escapes in the NVIDIA Container Toolkit; build-and-run PoCs.
  • references/k8s-rbac-escalation.md — RBAC privilege escalation (wildcards, escalate/bind, pods/exec, impersonation), SA-token harvest, the nodes/proxy GET → kubelet WebSocket exec RCE, and open kubelet :10250.
  • references/ingress-admission-attacks.md — IngressNightmare (CVE-2025-1974 + the annotation-injection chain), admission-webhook abuse, and how a controller SA leads to cluster-wide secret theft.
  • references/node-host-pivot.md — post-escape playbook: from one node to the whole cluster — etcd looting, kubelet/crictl, SA-token mining across pods, cloud IMDS role theft, and the defensive counterweight.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.