Description

Watches and sends kubernetes resource-related events

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
komodor-agentdefault876Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 komodor-agent

Namespace: default  |  Automount:

🔑 Permissions (87)

RoleResourceVerbsRiskTags
ClusterRole komodor-agent*delete · get · list · watchCriticalAuthorizationBypass ClusterAdminAccess ClusterStructure ClusterWideAccess ClusterWideLogAccess (+24 more)
ClusterRole komodor-agentcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole komodor-agentbatch/cronjobscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole komodor-agentapps/daemonsetscreate · delete · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole komodor-agentapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole komodor-agentbatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole komodor-agentnetworking.k8s.io/networkpoliciescreate · delete · get · list · patch · update · watchCriticalDenialOfService LateralMovement NetworkManipulation NetworkPolicyManagement Tampering
ClusterRole komodor-agentcore/nodes/proxyget · listCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole komodor-agentcore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole komodor-agentcore/pods/execcreateCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole komodor-agentcore/secretscreate · delete · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole komodor-agentcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole komodor-agentapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole komodor-agentnetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole komodor-agentcore/pods/logget · listHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
ClusterRole komodor-agentcore/pods/portforwardcreateHighClusterWidePodPortForward LateralMovement NetworkManipulation PodPortForward
ClusterRole komodor-agentrbac.authorization.k8s.io/clusterrolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole komodor-agentrbac.authorization.k8s.io/clusterrolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole komodor-agentstorage.k8s.io/csinodesget · list · watchMediumInformationDisclosure NodeAccess Reconnaissance StorageDetailsDisclosure
ClusterRole komodor-agentcore/eventsget · list · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole komodor-agentadmissionregistration.k8s.io/mutatingwebhookconfigurationsget · list · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole komodor-agentcore/resourcequotasget · list · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole komodor-agentrbac.authorization.k8s.io/rolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole komodor-agentrbac.authorization.k8s.io/rolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole komodor-agentadmissionregistration.k8s.io/validatingwebhookconfigurationsget · list · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole komodor-agentargoproj.io/analysistemplatesget · list · watchLow
ClusterRole komodor-agentcertificates.k8s.io/certificatesigningrequestsget · list · watchLow
ClusterRole komodor-agentargoproj.io/clusteranalysistemplatesget · list · watchLow
ClusterRole komodor-agentrbac/clusterrolebindingsget · list · watchLow
ClusterRole komodor-agentrbac/clusterrolesget · list · watchLow
ClusterRole komodor-agentargoproj.io/clusterworkflowtemplatesget · list · watchLow
ClusterRole komodor-agentapps/controllerrevisionsget · list · watchLow
ClusterRole komodor-agentargoproj.io/cronworkflowsget · list · watchLow
ClusterRole komodor-agentstorage.k8s.io/csidriversget · list · watchLow
ClusterRole komodor-agentstorage.k8s.io/csistoragecapacitiesget · list · watchLowInformationDisclosure Reconnaissance StorageDetailsDisclosure
ClusterRole komodor-agentapiextensions.k8s.io/customresourcedefinitionsget · list · watchLow
ClusterRole network-mapper-apps/daemonsetsgetLow
ClusterRole network-mapper-apps/deploymentsgetLow
ClusterRole komodor-agentapps/deployments/scalepatchLow
ClusterRole komodor-agentcore/endpointsget · list · watchLow
ClusterRole network-mapper-core/endpointsget · list · watchLow
ClusterRole komodor-agentdiscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole komodor-agentflowcontrol.apiserver.k8s.io/flowschemasget · list · watchLow
ClusterRole komodor-agentautoscaling/horizontalpodautoscalersget · list · watchLow
ClusterRole komodor-agentextensions/ingressclassesget · list · watchLow
ClusterRole komodor-agentnetworking.k8s.io/ingressclassesget · list · watchLow
ClusterRole komodor-agentextensions/ingressesget · list · watchLow
ClusterRole komodor-agentcoordination.k8s.io/leasesget · list · watchLow
ClusterRole komodor-agentcore/limitrangesget · list · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole komodor-agentauthorization.k8s.io/localsubjectaccessreviewsget · list · watchLow
ClusterRole komodor-agentcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole network-mapper-core/namespacesgetLow
ClusterRole komodor-agentextensions/networkpoliciesget · list · watchLow
ClusterRole komodor-agentcore/nodesget · list · patch · watchLow
ClusterRole komodor-agentmetrics.k8s.io/nodesget · list · watchLow
ClusterRole komodor-agentcore/nodes/statsget · listLow
ClusterRole komodor-agentcore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole komodor-agentcore/persistentvolumescreate · delete · get · list · patch · update · watchLow
ClusterRole komodor-agentpolicy/poddisruptionbudgetsget · list · watchLow
ClusterRole network-mapper-core/podsget · list · watchLow
ClusterRole komodor-agentmetrics.k8s.io/podsget · list · watchLow
ClusterRole komodor-agentcore/pods/evictioncreateLow
ClusterRole komodor-agentpolicy/podsecuritypoliciesget · list · watchLow
ClusterRole komodor-agentcore/podtemplatesget · list · watchLow
ClusterRole komodor-agentscheduling.k8s.io/priorityclassesget · list · watchLow
ClusterRole komodor-agentflowcontrol.apiserver.k8s.io/prioritylevelconfigurationsget · list · watchLow
ClusterRole komodor-agentapps/replicasetscreate · delete · get · list · patch · update · watchLow
ClusterRole network-mapper-apps/replicasetsgetLow
ClusterRole komodor-agentcore/replicationcontrollersget · list · watchLow
ClusterRole komodor-agentrbac/rolebindingsget · list · watchLow
ClusterRole komodor-agentrbac/rolesget · list · watchLow
ClusterRole komodor-agentargoproj.io/rolloutsget · list · watchLow
ClusterRole komodor-agentargoproj.io/rollouts/finalizersget · list · watchLow
ClusterRole komodor-agentargoproj.io/rollouts/statusget · list · watchLow
ClusterRole komodor-agentnode.k8s.io/runtimeclassesget · list · watchLow
ClusterRole komodor-agentauthorization.k8s.io/selfsubjectaccessreviewsget · list · watchLow
ClusterRole komodor-agentauthorization.k8s.io/selfsubjectrulesreviewsget · list · watchLow
ClusterRole komodor-agentcore/serviceaccountsget · list · watchLow
ClusterRole network-mapper-apps/statefulsetsgetLow
ClusterRole komodor-agentapps/statefulsets/scalepatchLow
ClusterRole komodor-agentcore/storageclassescreate · delete · patch · updateLow
ClusterRole komodor-agentstorage.k8s.io/storageclassesget · list · watchLow
ClusterRole komodor-agentauthorization.k8s.io/subjectaccessreviewsget · list · watchLow
ClusterRole komodor-agentstorage.k8s.io/volumeattachmentsget · list · watchLow
ClusterRole komodor-agentargoproj.io/workflowsget · list · watchLow
ClusterRole komodor-agentargoproj.io/workflowtemplatesget · list · watchLow
Role network-mapper-core/configmaps (restricted to: network-mapper-store-)get · updateLowResourceNameRestricted

⚠️ Potential Abuse (48)

The following security risks were found based on the above permissions:

📦 Workloads (6)

KindNameContainerImage
DaemonSetkomodor-agent-daemonmetricspublic.ecr.aws/komodor-public/telegraf:1.29.1-alpine
DaemonSetkomodor-agent-daemonnetwork-sniffer-public.ecr.aws/komodor-public/network-mapper-sniffer:v1.0.3
DaemonSetkomodor-agent-daemonnode-enricherpublic.ecr.aws/komodor-public/komodor-agent:0.2.70
Deploymentkomodor-agentk8s-watcherpublic.ecr.aws/komodor-public/komodor-agent:0.2.70
Deploymentkomodor-agentnetwork-mapperpublic.ecr.aws/komodor-public/network-mapper:v1.0.3
Deploymentkomodor-agentsupervisorpublic.ecr.aws/komodor-public/komodor-agent:0.2.70