Suspicious curl user agent
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT, Containers
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Application Layer Protocol: Web Protocols (T1071.001)
Severity
Informational
Description
Suspicious user agent provided to curl command.
Attacker's Goals
Impairing host defenses.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Variations
PreviousSuspicious container runtime connection from within a Kubernetes Pod
NextSuspicious data encryption
Was this helpful?
