← LibraryTechnique entry
K-SA-TOKENDiscovery
ServiceAccount Token Theft
Read /var/run/secrets/kubernetes.io/serviceaccount/token from a compromised pod — talk to the API server as the pod's SA.
§ Where this technique fits
K-SA-TOKEN is catalogued under the Discovery tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 5 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01Malicious CronJob / DaemonSetseen 1×K-CRONJOB-PERSIST · Persistence