For the complete documentation index, see llms.txt. This page is also available as Markdown.

A contained executable from a mounted share initiated a suspicious outbound network connection

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Escape to Host (T1611)

Severity

Medium

Description

A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical.

Attacker's Goals

Gain high privileged command execution on the host machine via one of its running containers.

Investigative actions

  • Check if the requested IP address is known or malicious.

  • Investigate the contained process and its process tree.

Variations

A contained executable from a mounted share initiated a suspicious outbound network connection

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Escape to Host (T1611)

Severity

Medium

Description

A cloud machine contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical.

Attacker's Goals

Gain high privileged command execution on the host machine via one of its running containers.

Investigative actions

  • Check if the requested IP address is known or malicious.

  • Investigate the contained process and its process tree.

Was this helpful?