Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapKubernetes vulnerability scanner activity Medium 1 variation
A Kubernetes cluster was scanned by a known vulnerability scanner.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Discovery (TA0007)ATT&CK techniques: Deploy Container (T1610) Container and Resource Discovery (T1613)Required data: XDR AgentDetector tags: Kubernetes - AGENTAttacker's goals: Usage of known tools and frameworks to exploit Kubernetes clusters.Investigative actions: Check if there is an active attack against the Kubernetes cluster.Variations
Kubernetes vulnerability scanner activity from within a Kubernetes Pod
Medium overridden
A Kubernetes cluster was scanned by a known vulnerability scanner from within a container. overridden