Suspicious process execution in a privileged container
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT, Containers
ATT&CK Tactic
Execution (TA0002), Privilege Escalation (TA0004)
ATT&CK Technique
Container Administration Command (T1609), Escape to Host (T1611)
Severity
Informational
Description
A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days.
Attacker's Goals
Perform lateral movement to new hosts to expand the foothold within a network and gain higher privileges.
Investigative actions
Investigate the processes being spawned on the host for malicious activities.
Correlate the command run from the host and understand which software initiated it.
Variations
PreviousSuspicious process execution from tmp folder
NextSuspicious process loads a known PowerShell module
Was this helpful?
