A contained executable was executed by an unusual process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Privilege Escalation (TA0004), Persistence (TA0003)
ATT&CK Technique
Escape to Host (T1611), Boot or Logon Autostart Execution: Kernel Modules and Extensions (T1547.006)
Severity
Medium
Description
A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical.
Attacker's Goals
Gain high privileged command execution on the host machine via one of its running containers.
Investigative actions
Check what actions were made after the suspicious file execution.
Investigate the contained process and its process tree.
Variations
PreviousA contained executable from a mounted share initiated a suspicious outbound network connection
NextA contained process attempted to escape using the 'notify on release' feature
Was this helpful?
