Skip to content

accuknox/k8s-sandcat

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

13 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Caldera sandcat for k8s

MITRE Caldera provides a bunch of agents that can be used out of the box for adversarial emulation. Sandcat is one of the most widely used agent/plugin for Linux environments.

This repository provides a k8s deployment for MITRE Caldera Sandcat Agent.

  • k8s cluster-admin role for caldera-agent to simulate attacks effectively
  • Once the k8s-sandcat deployment is deployed, the agents pod name will show up on Caldera Server.

K8s Sandcat Configuration

There are two primary configurations:

  1. Caldera server to use
  2. Group name to use for the agent

Both these configuration are part of the deployment manifest.