Case 33D9BA · Cloud · L3 Applied
Crypto-Miner in the Cluster
Practise as: Incident drill · Interview
Live alertNode CPU pinned at 100%. A pod named kube-proxy-x7f2 in the default namespace is connecting to a mining pool on port 3333.
Interview questionYou find a crypto-miner running in production Kubernetes. How do you work out how it got there?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Isolate with a deny-all NetworkPolicy and cordon the node; capture pod spec, image and logs before deleting
- Find the entry point: exposed dashboard or kubelet API, a vulnerable app, or leaked kubeconfig/service account
- Check audit logs for who created the pod and what else that identity did (secrets read, other workloads)
- Assume the node may be compromised if the pod was privileged or had host mounts; rebuild rather than clean
- Harden: admission policies blocking unknown registries and privileged pods, and egress restrictions
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.