Kill Chains and Coffee

Cloud Compromise & OT Reachability | Kill Chains and Coffee

Episode Summary

Discover how low-priority vulnerabilities turn into complete kill chains in the AI era. In this episode of “Kill Chains and Coffee," Armadin Founder and Chief Offensive Security Officer Evan Peña joins host Greg Heon to discuss two kill chains Armadin recently discovered. Kill chain 1 progressed from SSRF to API remote code execution (RCE) to Kubernetes and the cloud. Kill chain 2 went from an assumed breach to an operational technology (OT) environment. The kill chain 1 entry point was unauthenticated SSRF via a manipulated HTTP header. The SSRF chained to API RCE, landing the Armadin attacker in a Kubernetes pod. Reconnaissance on the pod revealed a local database with service account credentials stored in clear text. The attacker used a privileged container to mount the host OS and break out of the pod—accessing an AWS tenant, additional pods, cloud accounts, and production data. Key takeaway: SSRF alone looked like a low-priority issue, but the full kill chain revealed production data exposure. Kill chain 2 started with a low-privileged domain account on a Windows Server 2019 host, where the Armadin attacker gained access through a 5-year-old critical CVE (Print Nightmare). The payload was delivered via a Microsoft Defender AV exclusion folder configured for a third-party security tool. The attacker then found a local building management system (BMS) database, where it accessed sensor data, OT network views, and multiple protocols. The customer had run annual penetration tests for a decade but had never surfaced the OT issue. The AI-powered Armadin attacker had the scale and speed to cover the entire attack surface: all paths in, all the time. For security teams: This type of repeatable controlled assessment gives you the tools and confidence to identify truly exploitable risk across your environment.

Episode Notes

Discover how low-priority vulnerabilities turn into complete kill chains in the AI era.

In this episode of “Kill Chains and Coffee," Armadin Founder and Chief Offensive Security Officer Evan Peña joins host Greg Heon to discuss two kill chains Armadin recently discovered.

Kill chain 1 progressed from SSRF to API remote code execution (RCE) to Kubernetes and the cloud. Kill chain 2 went from an assumed breach to an operational technology (OT) environment.

The kill chain 1 entry point was unauthenticated SSRF via a manipulated HTTP header. The SSRF chained to API RCE, landing the Armadin attacker in a Kubernetes pod. Reconnaissance on the pod revealed a local database with service account credentials stored in clear text.

The attacker used a privileged container to mount the host OS and break out of the pod—accessing an AWS tenant, additional pods, cloud accounts, and production data. Key takeaway: SSRF alone looked like a low-priority issue, but the full kill chain revealed production data exposure.

Kill chain 2 started with a low-privileged domain account on a Windows Server 2019 host, where the Armadin attacker gained access through a 5-year-old critical CVE (Print Nightmare). The payload was delivered via a Microsoft Defender AV exclusion folder configured for a third-party security tool. The attacker then found a local building management system (BMS) database, where it accessed sensor data, OT network views, and multiple protocols.

The customer had run annual penetration tests for a decade but had never surfaced the OT issue. The AI-powered Armadin attacker had the scale and speed to cover the entire attack surface: all paths in, all the time.

For security teams: This type of repeatable controlled assessment gives you the tools and confidence to identify truly exploitable risk across your environment.

RESOURCES 
Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-3-ssrf-to-api-rce 
Armadin Offensive Security Platform: https://armadin.com/platform 
Request a Demo: https://www.armadin.com/request-a-demo 

CONNECT WITH ARMADIN 
Website: https://armadin.com 
LinkedIn:   / armadin   
Twitter/X: https://x.com/armadinsecurity