Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Mount command was executed from within a Kubernetes pod to list all the attached filesystems Low 1 variation

    The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Escape to Host (T1611)
    Required data: XDR Agent
    Detector tags: Kubernetes - AGENT
    Attacker's goals: Access to the host filesystem.
    Investigative actions: Look for additional suspicious activities. Verify if there was an attempt to access the host system.

    Variations

    Unusual mount command was executed from within a Kubernetes pod to list all the attached filesystems

    Medium overridden

    The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access. overridden