Kubetier
  1. Patch an existing MutatingWebhookConfiguration to replace the clientConfig.url with an attacker-controlled endpoint

  2. All requests matching the webhook's existing rules are now proxied through the attacker server

  3. Capture SA tokens and secrets.

    Silently mutate pod specs or block deployments

K8s docs ↗