Open cardosec

Case 33D9BA · Cloud · L3 Applied

Crypto-Miner in the Cluster

Practise as: Incident drill · Interview

Live alertNode CPU pinned at 100%. A pod named kube-proxy-x7f2 in the default namespace is connecting to a mining pool on port 3333.

Interview questionYou find a crypto-miner running in production Kubernetes. How do you work out how it got there?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Isolate with a deny-all NetworkPolicy and cordon the node; capture pod spec, image and logs before deleting
  2. Find the entry point: exposed dashboard or kubelet API, a vulnerable app, or leaked kubeconfig/service account
  3. Check audit logs for who created the pod and what else that identity did (secrets read, other workloads)
  4. Assume the node may be compromised if the pod was privileged or had host mounts; rebuild rather than clean
  5. Harden: admission policies blocking unknown registries and privileged pods, and egress restrictions

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.