What problem does it solve?
This Skill eliminates the manual, error-prone work of identifying high-impact Kubernetes and Docker security misconfigurations, unpatched CVEs, and privilege escalation paths that lead to full cluster or host compromise during authorized penetration testing of containerized infrastructure.
Core Features & Use Cases
- Comprehensive K8s/Docker Enumeration: Fingerprints common Kubernetes and container management ports, detects anonymous API access, kubelet RCE vectors, unauthenticated etcd access, docker.sock exposure, and runc container escape vulnerabilities.
- Validated Impact Proof: Includes out-of-band confirmation gates, false positive killers, and step-by-step validation checklists to ensure findings are accurate and reportable, avoiding common misconfigurations like conflating read-only kubelet 10255 with exploitable 10250.
- Use Case: A red teamer assessing a cloud-native target can use this Skill to systematically validate anonymous API admin access, confirm kubelet /run RCE, and dump unencrypted etcd secrets without manual trial and error or false positive reporting.
Quick Start
Use the hunt-k8s skill to scan a target for exposed Kubernetes and Docker services, validate critical misconfigurations, and confirm RCE or credential leak vulnerabilities for your authorized penetration test.