Analytics BIOC Medium

A contained executable from a mounted share initiated a suspicious outbound network connection

A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Escape to Host (T1611)
Attacker's goals:

Gain high privileged command execution on the host machine via one of its running containers.

Investigative actions:

Check if the requested IP address is known or malicious. Investigate the contained process and its process tree.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • A contained executable from a mounted share initiated a suspicious outbound network connection Medium