Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0004 ✕ technique: T1611 ✕
Download CSV Show ATT&CK heatmapAccess to sensitive host files from within a Kubernetes pod Informational 2 variations
A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004)ATT&CK techniques: Escape to Host (T1611)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Kubernetes - AGENT, Kubernetes Credentials Theft AnalyticsAttacker's goals: Access to the host filesystem.Investigative actions: Look for additional suspicious activities. Verify if the exposed files were used for malicious activity. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.Variations
Access to sensitive host files from within a Kubernetes pod via an interactive shell
Medium overridden
A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt. overridden
Unusual access to sensitive host files from within a Kubernetes pod
Low overridden
A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt. overridden