EXPLORE
← Back to Explore
T1609

Container Administration Command

Adversaries may abuse a container administration service to execute commands within a container. A container administration service such as the Docker daemon, the Kubernetes API server, or the kubelet may allow remote management of containers within an environment.(Citation: Docker Daemon CLI)(Citation: Kubernetes API)(Citation: Kubernetes Kubelet) In Docker, adversaries may specify an entrypoint during container deployment that executes a script or command, or they may use a command such as <c...

Containers
17
Detections
2
Sources
1
Threat Actors

BY SOURCE

15elastic2sigma

PROCEDURES (10)

General Monitoring3 detections

Auto-extracted: 3 detections for general monitoring

Token2 detections

Auto-extracted: 2 detections for token

Unusual2 detections

Auto-extracted: 2 detections for unusual

Privilege2 detections

Auto-extracted: 2 detections for privilege

Cloud Monitoring2 detections

Auto-extracted: 2 detections for cloud monitoring

Persist2 detections

Auto-extracted: 2 detections for persist

Kubernetes1 detections

Auto-extracted: 1 detections for kubernetes

Api1 detections

Auto-extracted: 1 detections for api

Unusual1 detections

Auto-extracted: 1 detections for unusual

Token1 detections

Auto-extracted: 1 detections for token

THREAT ACTORS (1)

DETECTIONS (17)