★ Selected for Black Hat MEA Arsenal 2026

Make your cluster confess.

Ask questions in plain English and KubeConfess reports — with evidence — exactly how your Kubernetes cluster can be compromised.

  • Which identities can reach cluster-admin?
  • What is readable from a compromised pod?
  • Is this escalation path actually exploitable?
Statement of the Accusedcluster: prod-eu-1
FILE 0417
vulnerable-workloads
under caution
Guilty

The charges

Three ways to put a cluster on the record

Point KubeConfess at a kubeconfig, run it from inside a pod, or aim it at a single identity. Each is a distinct line of questioning.

line of questioning: interview

Query it in plain English

Point KubeConfess at a kubeconfig and interrogate live cluster state conversationally — which namespaces exist, what runs where, which service account a workload uses. No chaining kubectl flags, no memorizing RBAC verbs.

The same conversation surfaces the risks: it flags vulnerable workloads — privileged and root containers, dangerous host mounts — and audits permissions and RBAC, explaining why each finding matters and how to fix it.

  • Flags privileged/root containers and dangerous host-path mounts
  • Audits permissions and RBAC — cluster-admin and over-privileged bindings
  • Explains the security impact and the exact fix, not a raw YAML dump
arnav@cluster: ~/KubeConfess
line of questioning: under caution

Red-team it from the inside

Run KubeConfess in-cluster and it operates from a single pod's point of view — the exact blast radius of an attacker who already has a shell in the container. It never reaches past that pod's own service account.

Purpose-built for red teams, it doesn't stop at reporting. Where the pod's permissions allow, it executes the attack — stealing ServiceAccount tokens and harvesting readable secrets — so you leave with proof the path is exploitable, not a theory that it might be. And many more features for all.

  • Self-scans the pod: capabilities, host mounts, sockets, metadata endpoints, sensitive env vars
  • Token theft — decodes SA tokens and emits ready-to-use kubectl / curl commands
  • Secret harvesting — decodes and dumps real secret values, not just their names
root@juicy-pod: /KubeConfess
line of questioning: reconstruction

Map the full path to cluster-admin

Aim investigate at a pod, namespace, or service account and KubeConfess runs a fixed sequence of checks against it, then reconstructs the route to cluster-admin — bound roles, privileged containers, host mounts, and every secret reachable along the way.

You get a structured written report — and, by adding --graph, a rendered attack graph in the style of BloodHound for Active Directory.

  • Targets pod/<name>, namespace/<name>, or sa/<name>
  • Reports findings, attack paths, blast radius, and fixes in one shot
  • Add --graph to render the whole path as a graph
arnav@cluster: ~/KubeConfess

Evidence

The confession, drawn out as a map

Every investigation is also a graph: identities, workloads and secrets as nodes, the permissions between them as directed edges — so a whole escalation reads at a glance.

KUBECONFESS ATTACK GRAPH LIVE
RUNS_AS CAN_READ GRANTS_ACCESS CAN_EXEC_INTO LATERAL_MOVE Ppod-attack-testerpod · attacker shell Ssa-attack-testerservice account Sprod-db-credentialssecret EProduction Postgresexternal target Ppod-execpod · default ns

Hands-on lab

Practice on a cluster that's meant to be broken

No cluster handy, and nothing to install. A guided KillerCoda scenario spins up a deliberately vulnerable cluster in your browser with KubeConfess ready to run.

Run a full interrogation, end to end

Work through real misconfigurations on a live cluster — flag privileged workloads, audit RBAC, harvest secrets from inside a pod, and map an attack path to cluster-admin. Everything the demos above show, with your own hands on the keyboard and no risk to anything of your own.

Launch the lab → killercoda.com · runs in-browser

On the record

Everything it can do

A single agent, directed in whichever way the engagement calls for.

chat

Query namespaces, workloads, roles and service accounts in plain English, backed by live cluster state.

--kubeconfig

Full audits from your workstation, using any kubeconfig you already have.

--incluster

Runs as a pod and scopes itself to that pod's own service account — nothing more.

attack capabilities

Confirms a path by executing it — stealing static ServiceAccount tokens and harvesting readable secret values, wherever RBAC already permits. More attack modules on the way.

investigate <target>

Reconstructs the path from a pod, namespace, or service account to cluster-admin as a structured written report.

investigate … --graph

Adds a rendered attack graph to any investigation — the whole escalation, drawn out like BloodHound does for Active Directory.

extensible

Bring your own checks and attacks. Every tool is a small Python file with two exports — add one, register it, open a pull request, and it becomes available to everyone. See the contribution guide.

open source

MIT-licensed and developed in the open — read the code, file an issue, or submit a pull request.


Open case files

Add your own checks and attacks

KubeConfess is built to be extended. Its detections and exploitation techniques are modular, so the next check is one you can write.

Contribute a technique, ship it to everyone

Encode a misconfiguration you keep finding, or an escalation you've pulled off in the field, as a module. Open a pull request and, once merged, it runs for every KubeConfess user on their next scan. The tool gets sharper with every engagement the community brings back to it.

Good first contributions

Read the contribution guide

Start an interrogation

Bring a cluster in for questioning

KubeConfess is a Python CLI. Clone it, install it, and point it at a kubeconfig.

install.sh
# clone and enter the project
git clone https://github.com/arnavtripathy/KubeConfess.git
cd KubeConfess

# install into a virtualenv
python -m venv .venv && source .venv/bin/activate
pip install .

# set any OpenAI-compatible provider
export API_KEY="your-api-key-here"

# question a cluster from your workstation
kubeconfess --kubeconfig ~/.kube/config

# or, from inside a pod
kubeconfess --incluster

# map an attack path as a graph
you> investigate pod/nginx-abc -n payments --graph

Running from inside the cluster? Use --incluster — KubeConfess scopes itself to the pod it is running in and operates from there. See the README on GitHub for the full command reference.

Black Hat MEA Arsenal 2026

KubeConfess was selected to showcase at Black Hat MEA Arsenal 2026.