Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1204 ✕
Download CSV Show ATT&CK heatmapSuspicious docker image download from an unusual repository Informational 2 variations
The agent has pulled a docker image from a repository for the first time.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution: Malicious Image (T1204.003)Required data: XDR AgentDetector tags: Kubernetes - AGENT, ContainersAttacker's goals: Adversaries may rely on a user running a malicious image to facilitate execution.Investigative actions: Scan the docker image that was pulled. Check the repository designation. Check on which other agents the docker image is being used.Variations
Suspicious docker image download from an unrecognized registry
Low overridden
The agent has pulled a docker image from a registry that has never been used in the organization. overridden
Suspicious docker image download from an unrecognized repository
Low overridden
The agent has pulled a docker image from a repository that has never been used in the organization. overridden