A container registry was created or deleted
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs
Detection Modules
Cloud
Detector Tags
Kubernetes - API
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Data Destruction (T1485)
Severity
Informational
Description
A container registry was created or deleted.
Attacker's Goals
Gain access to sensitive data stored in the container registry.* Modify or delete existing data in the container registry.
Investigative actions
Check the activity logs to determine what was created or removed.
PreviousA contained process attempted to escape using the 'notify on release' feature
NextA disabled user attempted to authenticate via SSO
Was this helpful?
