Suspicious process execution from tmp folder
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT, Containers
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Hide Artifacts: Hidden Files and Directories (T1564.001)
Severity
Informational
Description
An unpopular process was executed from the tmp folder.
Attacker's Goals
Attackers may try to run the executable application from a folder that is writable to all users and use it to avoid detection.
Investigative actions
Verify that this isn't IT activity.
Look for other hosts executing similar commands.
Variations
PreviousSuspicious process executed with a high integrity level
NextSuspicious process execution in a privileged container
Was this helpful?
