Kubernetes-DNS-spoofing-POC

A proof-of-concept Python script showing a DNS spoofing attack in Kubernetes from a pod on a worker node. It is a security research demo of that attack path.

Share on XLicense: GPL-2.0

Overview

This is a proof-of-concept Python script that carries out a DNS spoofing attack in a Kubernetes environment, from a pod running on a worker server. It comes from CyberArk Labs research, and the README points to a CyberArk threat research blog post for background on the attack vector. It is a security research demonstration, not a general tool.

Key features

  • Python script demonstrating DNS spoofing in Kubernetes
  • Attack is run from a pod on a worker server
  • Linked CyberArk blog post explains the background

Best for

Security researchers and cluster defenders who want to understand this attack path. Use it only in environments you are authorized to test.

Upstream
C-h4ck-0/Kubernetes-DNS-spoofing-POC
Fork on GitHub
Guo-astro/Kubernetes-DNS-spoofing-POC
Upstream stars
15
Category
Security and networking
License
GPL-2.0
Forked
2021-03-16
Sync status
In syncLast synced 2026-09-29