1200KM / tool
Peirates — Attack Tool
Peirates is a post-exploitation Kubernetes exploitation framework with a focus on gathering service account tokens for lateral movement and privilege escalation. The tool is written in GoLang and publicly available on GitHub.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Peirates
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- TeamTNT · G0139 · Pinned relationship source (relationship--6d887394-6007-451e-beb9-0ce76b58ebc3)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1078.004 · Cloud Accounts · Detection rules & anomalies
- T1528 · Steal Application Access Token · Detection rules & anomalies
- T1530 · Data from Cloud Storage · Detection rules & anomalies
- T1550.001 · Application Access Token · Detection rules & anomalies
- T1552.005 · Cloud Instance Metadata API · Detection rules & anomalies
- T1552.007 · Container API · Detection rules & anomalies
- T1609 · Container Administration Command · Detection rules & anomalies
- T1610 · Deploy Container · Detection rules & anomalies
- T1611 · Escape to Host · Detection rules & anomalies
- T1613 · Container and Resource Discovery · Detection rules & anomalies
- T1619 · Cloud Storage Object Discovery · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Cloud Service Enumeration · DC0083
- Cloud Service Metadata · DC0070
- Cloud Service Modification · DC0069
- Cloud Storage Access · DC0025
- Cloud Storage Enumeration · DC0017
- Command Execution · DC0064
- Container Creation · DC0072
- Container Enumeration · DC0091
- Container Start · DC0077
- File Access · DC0055
- File Creation · DC0039
- Kernel Module Load · DC0031
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Pod Enumeration · DC0037
- Process Creation · DC0032
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- Volume Modification · DC0092
- Web Credential Usage · DC0007
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.