Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1611 ✕
Download CSV Show ATT&CK heatmapMount command was executed from within a Kubernetes pod to list all the attached filesystems Low 1 variation
The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004)ATT&CK techniques: Escape to Host (T1611)Required data: XDR AgentDetector tags: Kubernetes - AGENTAttacker's goals: Access to the host filesystem.Investigative actions: Look for additional suspicious activities. Verify if there was an attempt to access the host system.Variations
Unusual mount command was executed from within a Kubernetes pod to list all the attached filesystems
Medium overridden
The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access. overridden