Observed arrival · 2026-10-05
KubeConfess puts Kubernetes attack paths on the record
KubeConfess describes an agent that checks Kubernetes clusters for security issues and maps how an attacker could move toward cluster-admin.
- For
- Kubernetes administrators and authorized red teams
- Worth noticing
- In-cluster mode is described as limited to the pod’s own service account while tracing reachable escalation paths.
Field notes
The page lays out three investigation modes: conversational review from a kubeconfig, an in-cluster view bounded by the pod’s service account, and a fixed-sequence investigation aimed at a pod, namespace, or service account. Findings can include RBAC and workload risks, reachable secrets, fixes, and an optional graph of identities, workloads, secrets, and permission edges. The site also links to a live lab and GitHub; the extracted page does not establish their access requirements.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue