Pentest em cluster K8s — RBAC, Pod Security, network policy, service account, container escape, supply chain de imagem.
Why now
K8s adoção explodiu em fintech, SaaS e healthtech BR. Adoção rápida + complexidade enorme + RBAC confuso = produção com kubelet exposto, ServiceAccount com cluster-admin, imagens base com CVE crítica e network policy default-allow.
Applicable frameworks
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Cluster-admin abuse, namespace boundary, default SA com poderes, JWT projetado.
PodSecurityPolicy/PodSecurityAdmission, OPA Gatekeeper, Kyverno bypass, privileged pod.
Default-allow, east-west sem segregação, Ingress controller misconfig, service mesh.
Capabilities excessivas, hostNetwork, hostPID, volume mount sensível (/, /var/run/docker.sock).
Imagens base com CVE, secrets em camadas, image signature, registry auth.
etcd exposto, kubelet sem auth, API server público, cloud controller.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Cluster K8s de fintech regulada e SaaS B2B com workload PCI/LGPD.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Não. EKS tem IRSA, GKE tem workload identity, AKS tem managed identity. Cada um com seu vetor próprio. Auditamos cada um com playbook específico.
Sim. Auditamos mTLS, authorization policy, sidecar injection, control plane.
Cluster pequeno: R$ 15-30k. Multi-cluster: R$ 40-90k. Plataforma K8s com 20+ clusters: R$ 80-200k.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.