Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0007 ✕ technique: T1613 ✕
Download CSV Show ATT&CK heatmapSuspicious container reconnaissance activity in a Kubernetes pod Informational 2 variations
A process performed multiple consecutive container discovery commands from within a Kubernetes Pod.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 10 Minutes
- Deduplication:
- 1 Day
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Remote System Discovery (T1018) System Information Discovery (T1082) System Network Configuration Discovery (T1016) System Service Discovery (T1007) Container and Resource Discovery (T1613)Required data: XDR AgentDetector tags: Kubernetes - AGENT, ContainersAttacker's goals: Collect information about the host, network and user configuration for lateral movement and privilege escalation.Investigative actions: Verify if the script or process initiating the discovery commands is benign. Verify that this isn't sanctioned IT activity. Look for other hosts executing similar commands.Variations
Suspicious container reconnaissance activity in a Kubernetes pod
Medium overridden
A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. overridden
Suspicious container reconnaissance activity in a Kubernetes pod
Low overridden
A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. overridden