A contained executable from a mounted share initiated a suspicious outbound network connection
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Escape to Host (T1611)
Severity
Medium
Description
A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical.
Attacker's Goals
Gain high privileged command execution on the host machine via one of its running containers.
Investigative actions
Check if the requested IP address is known or malicious.
Investigate the contained process and its process tree.
Variations
PreviousA computer account was promoted to DC
NextA contained executable was executed by an unusual process
Was this helpful?
