Skip to content
← LibraryTechnique entry
K-HOSTPATH-MOUNTPrivilege Escalation

hostPath Volume Mount

Mount the host filesystem into a pod (read-write or even read-only of /etc/shadow) — exfil host secrets and pivot.

§ Where this technique fits

K-HOSTPATH-MOUNT is catalogued under the Privilege Escalation tactic of the offensive-security kill-chain. It appears in 5 approved dossiers in the registry, typically at step 4.6 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    SSH authorized_keys Backdoor
    L-SSH-AUTHKEYS · Persistence
    seen 1×
  2. 02
    ServiceAccount Token Theft
    K-SA-TOKEN · Discovery
    seen 1×
  3. 03
    Unsecured Credentials
    T1552 · Credential Access
    seen 1×