Compliance Node Overview
MITRE ATT&CK T1552.007 (Container API) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may gather credentials via APIs within a containers environment. APIs in these environments, such as the Docker API and Kubernetes APIs, allow a user to remotely manage their container resources and cluster components. An adversary may access the Docker API to collect logs that contain credentials to cloud, container, and various other resources in the environment. Affected platforms: Containers. MITRE-documented mitigations include M1026 Privileged Account Management, M1035 Limit Access to Resource Over Network, M1030 Network Segmentation, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-16, AC-17, AC-18.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1552/007/
SHA-256 integrity: 7109786bfaa23df15c66a9a4ad0202845aedd763d4f2c34af3d71bab7511eb03
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1552.007: Container API (https://attack.mitre.org/techniques/T1552/007/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access