Skip to content

Christophe Tafani-Dereeper

Personal tech and security blog about things I like, use, dislike and misuse.

Main Navigation

  • Home
  • Cloud Security
  • Windows Security
  • Active Directory Hunting Lab
  • About me

Category: Container Security

Stop worrying about ‘allowPrivilegeEscalation’

christophetd 4 March 2025 14 June 2024 Leave a Comment on Stop worrying about ‘allowPrivilegeEscalation’
Stop worrying about ‘allowPrivilegeEscalation’

Kubernetes’ ‘allowPrivilegeEscalation’ is a useful but poorly understood security hardening setting. Let’s dive into how it works and debunk some common myths about it.

Primary Sidebar


Suggestion? Question? Comment? Drop me a line via e-mail or Twitter!

Latest Posts

  • The New PKCE Authentication in AWS SSO Brings Hope (Mostly) 29 November 2024
  • Stop worrying about ‘allowPrivilegeEscalation’ 14 June 2024
  • IMDSv2 enforcement: coming to a region near you! 28 March 2024
  • Hiding in Plain Sight: Unlinking Malicious DLLs from the PEB 21 April 2023
  • A Tribute to Hadrien Milano 4 August 2022
  • MitM at the Edge: Abusing Cloudflare Workers 29 June 2022
  • Introducing Stratus Red Team, an Adversary Emulation Tool for the Cloud 28 January 2022
  • Implementing a Vulnerable AWS DevOps Environment as a CloudGoat Scenario 11 January 2022
  • Cloud Security Breaches and Vulnerabilities: 2021 in Review 22 December 2021
  • Phishing for AWS credentials via AWS SSO device code authentication (updated 2024) 9 June 2021

Tags

aws azure bash cloudflare git kubernetes lab linux malware offensive security sftp windows windows-internals write-up

Christophe Tafani-Dereeper © 2025 . All Rights Reserved

Theme by Suri