Account Manipulation: Additional Container Cluster Roles

Threat Actors may add additional roles or permissions to Threat Actors-controlled user or service account to maintain persistent access to a container orchestration system. For example, Threat Actors with sufficient permissions may create a RoleBinding or a ClusterRoleBinding to bind a Role or ClusterRole to a Kubernetes account. Where attribute-based access control (ABAC) is in use, Threat Actors with sufficient permissions may modify a Kubernetes ABAC policy to give the target account additional permissions.

ID: ATAGS-T1080.003
Sub-technique of:  ATAGS-T1080
Targeted Components: Cloud Control Plane
Responsibility: Provider
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.