Make your cluster confess.
Ask questions in plain English and KubeConfess reports — with evidence — exactly how your Kubernetes cluster can be compromised.
- Which identities can reach cluster-admin?
- What is readable from a compromised pod?
- Is this escalation path actually exploitable?
Three ways to put a cluster on the record
Point KubeConfess at a kubeconfig, run it from inside a pod, or aim it at a single identity. Each is a distinct line of questioning.
Query it in plain English
Point KubeConfess at a kubeconfig and interrogate live cluster state conversationally — which namespaces exist, what runs where, which service account a workload uses. No chaining kubectl flags, no memorizing RBAC verbs.
The same conversation surfaces the risks: it flags vulnerable workloads — privileged and root containers, dangerous host mounts — and audits permissions and RBAC, explaining why each finding matters and how to fix it.
- Flags privileged/root containers and dangerous host-path mounts
- Audits permissions and RBAC — cluster-admin and over-privileged bindings
- Explains the security impact and the exact fix, not a raw YAML dump
Red-team it from the inside
Run KubeConfess in-cluster and it operates from a single pod's point of view — the exact blast radius of an attacker who already has a shell in the container. It never reaches past that pod's own service account.
Purpose-built for red teams, it doesn't stop at reporting. Where the pod's permissions allow, it executes the attack — stealing ServiceAccount tokens and harvesting readable secrets — so you leave with proof the path is exploitable, not a theory that it might be. And many more features for all.
- Self-scans the pod: capabilities, host mounts, sockets, metadata endpoints, sensitive env vars
- Token theft — decodes SA tokens and emits ready-to-use
kubectl/curlcommands - Secret harvesting — decodes and dumps real secret values, not just their names
Map the full path to cluster-admin
Aim investigate at a pod, namespace, or service account and KubeConfess runs a fixed sequence of checks against it, then reconstructs the route to cluster-admin — bound roles, privileged containers, host mounts, and every secret reachable along the way.
You get a structured written report — and, by adding --graph, a rendered attack graph in the style of BloodHound for Active Directory.
- Targets
pod/<name>,namespace/<name>, orsa/<name> - Reports findings, attack paths, blast radius, and fixes in one shot
- Add
--graphto render the whole path as a graph
The confession, drawn out as a map
Every investigation is also a graph: identities, workloads and secrets as nodes, the permissions between them as directed edges — so a whole escalation reads at a glance.
Practice on a cluster that's meant to be broken
No cluster handy, and nothing to install. A guided KillerCoda scenario spins up a deliberately vulnerable cluster in your browser with KubeConfess ready to run.
Run a full interrogation, end to end
Work through real misconfigurations on a live cluster — flag privileged workloads, audit RBAC, harvest secrets from inside a pod, and map an attack path to cluster-admin. Everything the demos above show, with your own hands on the keyboard and no risk to anything of your own.
Everything it can do
A single agent, directed in whichever way the engagement calls for.
chatQuery namespaces, workloads, roles and service accounts in plain English, backed by live cluster state.
--kubeconfigFull audits from your workstation, using any kubeconfig you already have.
--inclusterRuns as a pod and scopes itself to that pod's own service account — nothing more.
attack capabilitiesConfirms a path by executing it — stealing static ServiceAccount tokens and harvesting readable secret values, wherever RBAC already permits. More attack modules on the way.
investigate <target>Reconstructs the path from a pod, namespace, or service account to cluster-admin as a structured written report.
investigate … --graphAdds a rendered attack graph to any investigation — the whole escalation, drawn out like BloodHound does for Active Directory.
extensibleBring your own checks and attacks. Every tool is a small Python file with two exports — add one, register it, open a pull request, and it becomes available to everyone. See the contribution guide.
open sourceMIT-licensed and developed in the open — read the code, file an issue, or submit a pull request.
Add your own checks and attacks
KubeConfess is built to be extended. Its detections and exploitation techniques are modular, so the next check is one you can write.
Contribute a technique, ship it to everyone
Encode a misconfiguration you keep finding, or an escalation you've pulled off in the field, as a module. Open a pull request and, once merged, it runs for every KubeConfess user on their next scan. The tool gets sharper with every engagement the community brings back to it.
Good first contributions
- A new misconfiguration or security check
- An attack or post-exploitation module
- Pick up an open issue
Bring a cluster in for questioning
KubeConfess is a Python CLI. Clone it, install it, and point it at a kubeconfig.
# clone and enter the project git clone https://github.com/arnavtripathy/KubeConfess.git cd KubeConfess # install into a virtualenv python -m venv .venv && source .venv/bin/activate pip install . # set any OpenAI-compatible provider export API_KEY="your-api-key-here" # question a cluster from your workstation kubeconfess --kubeconfig ~/.kube/config # or, from inside a pod kubeconfess --incluster # map an attack path as a graph you> investigate pod/nginx-abc -n payments --graph
Running from inside the cluster? Use --incluster — KubeConfess scopes itself to the pod it is running in and operates from there. See the README on GitHub for the full command reference.
KubeConfess was selected to showcase at Black Hat MEA Arsenal 2026.