Private container image pushed to a public registry — embedded credentials at risk
A medium Cloud Infrastructure scenario on Public Container Image Credential Leak.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 3 templates in this Track + Difficulty pool.
catalog id · cloud-public-container-image-leak
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Contain a private container image leaked to a public registry
- Rotate embedded credentials and harden registry/build controls
- Unsecured Credentials: Credentials In Files · Credential AccessT1552.001 · TA0006MappedHigh confidence
Trains response to a cloud credential baked into a container image layer and leaked on a public registry.
- User Account ContainmentD3-UACMappedHigh confidence
Trains rotating and revoking the embedded credential once the image is public.
- Resource Access Policy AuditingD3-RAPAMappedMedium confidence
Trains correcting the registry visibility and scoping the build identity that pushed it public.
- Data Security · ProtectPR.DS · PRMappedHigh confidence
Trains the data-security posture that keeps secrets out of build artifacts.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection from secret scanning and registry monitoring of a public push.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains rotating the credential and making the image private as containment.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains scoping what the image exposes and whether the leaked credential was used.
- Secure Sensitive Data2.IMappedHigh confidence
Trains the sensitive-data baseline that keeps credentials out of public artifacts.
- Log Collection2.TMappedMedium confidence
Trains preserving registry push/pull logs that scope the exposure.
- Data ProtectionControl 3MappedHigh confidence
Trains the data-protection control behind rotating and removing the leaked secret.
- Application Software SecurityControl 16MappedMedium confidence
Trains the secure-build practice of injecting secrets at runtime, not baking them into images.