EXPLORE
← Back to Explore
T1609

Container Administration Command

Adversaries may abuse a container administration service to execute commands within a container. A container administration service such as the Docker daemon, the Kubernetes API server, or the kubelet may allow remote management of containers within an environment.(Citation: Docker Daemon CLI)(Citation: Kubernetes API)(Citation: Kubernetes Kubelet) In Docker, adversaries may specify an entrypoint during container deployment that executes a script or command, or they may use a command such as <c...

Containers
26
Detections
2
Sources
1
Threat Actors

BY SOURCE

23elastic3sigma

PROCEDURES (16)

Privilege2 detections

Auto-extracted: 2 detections for privilege

Container2 detections

Auto-extracted: 2 detections for container

Persist2 detections

Auto-extracted: 2 detections for persist

Inject2 detections

Auto-extracted: 2 detections for inject

Credential2 detections

Auto-extracted: 2 detections for credential

Lateral2 detections

Auto-extracted: 2 detections for lateral

Container2 detections

Auto-extracted: 2 detections for container

Bypass2 detections

Auto-extracted: 2 detections for bypass

Token2 detections

Auto-extracted: 2 detections for token

Unusual2 detections

Auto-extracted: 2 detections for unusual

Token1 detections

Auto-extracted: 1 detections for token

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

Kubernetes1 detections

Auto-extracted: 1 detections for kubernetes

Unusual1 detections

Auto-extracted: 1 detections for unusual

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

General Monitoring1 detections

Auto-extracted: 1 detections for general monitoring

THREAT ACTORS (1)

DETECTIONS (26)

Container Management Utility Execution Detected via Defend for Containers
elasticlow
Container Management Utility Run Inside A Container
elasticlow
Container Runtime CLI Execution with Suspicious Arguments
elasticmedium
Direct Interactive Kubernetes API Request by Common Utilities
elasticmedium
Direct Interactive Kubernetes API Request by Unusual Utilities
elasticlow
Direct Interactive Kubernetes API Request Detected via Defend for Containers
elasticlow
Docker Socket Enumeration
elasticmedium
Forbidden Direct Interactive Kubernetes API Request
elasticmedium
Interactive Exec Into Container Detected via Defend for Containers
elasticlow
Kubectl Apply Pod from URL
elasticlow
Kubernetes Ephemeral Container Added to Pod
elasticmedium
Kubernetes Pod Exec Cloud Instance Metadata Access
elastichigh
Kubernetes Pod Exec Potential Reverse Shell
elastichigh
Kubernetes Pod Exec Sensitive File or Credential Path Access
elastichigh
Kubernetes Pod Exec with Curl or Wget to HTTPS
elastichigh
Kubernetes Potential Enumeration Activity
sigmamedium
Kubernetes User Exec into Pod
elasticmedium
Pod or Container Creation with Suspicious Command-Line
elasticmedium
Potential Kubectl Masquerading via Unexpected Process
elasticmedium
Potential Kubeletctl Execution
elasticmedium
Potential Kubeletctl Execution Detected via Defend for Containers
elastichigh
Potential Remote Command Execution In Pod Container
sigmamedium
Potential Sidecar Injection Into Running Deployment
sigmamedium
Privileged Container Creation with Host Directory Mount
elastichigh
Privileged Docker Container Creation
elasticmedium
Suspicious Container Runtime CLI Execution
elasticmedium