Graph Nodes
| Node Type | Represents |
|---|---|
| Pod | Running workload (entry point) |
| ServiceAccount | Kubernetes identity |
| Role / ClusterRole | Permission set |
| Binding | Links identity to permissions |
| Resource | Target (secrets, pods/exec, RBAC) |
What It Finds
- Pod → cluster-admin: full cluster control from a compromised pod
- Pod → secrets access: reading secrets in other namespaces
- Pod → pod exec: lateral movement to other pods
- Escalation chains: self-grant cluster-admin via RoleBinding creation