For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual Process Spawned by Nginx in Ingress-Nginx pod

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

Kubernetes - AGENT, Containers

ATT&CK Tactic

Execution (TA0002), Initial Access (TA0001)

ATT&CK Technique

Command and Scripting Interpreter (T1059), Exploit Public-Facing Application (T1190)

Severity

Low

Description

Unusual Process Spawned by Nginx in Ingress-Nginx pod.

Attacker's Goals

An attacker attempts to use nginx for lateral movement or privilege escalation.

Investigative actions

  • Investigate the child processes for malicious activity and network connections to an external host.

Variations

Unusual process spawned by ingress-nginx with a critical-severity vulnerability found the workload

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Initial Access (TA0001)

ATT&CK Technique

Command and Scripting Interpreter (T1059), Exploit Public-Facing Application (T1190)

Severity

High

Description

Unusual Process Spawned by Nginx in Ingress-Nginx pod.

Attacker's Goals

An attacker attempts to use nginx for lateral movement or privilege escalation.

Investigative actions

  • Investigate the child processes for malicious activity and network connections to an external host.

Was this helpful?