Mount command was executed from within a Kubernetes pod to list all the attached filesystems
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Escape to Host (T1611)
Severity
Low
Description
The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access.
Attacker's Goals
Access to the host filesystem.
Investigative actions
Look for additional suspicious activities.
Verify if there was an attempt to access the host system.
Variations
Was this helpful?
