Analytics BIOC
Medium
✕
A contained executable was executed by an unusual process
A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Escape to Host (T1611) Boot or Logon Autostart Execution: Kernel Modules and Extensions (T1547.006)
Attacker's goals:
Gain high privileged command execution on the host machine via one of its running containers.
Investigative actions:
Check what actions were made after the suspicious file execution. Investigate the contained process and its process tree.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- A contained executable was executed by the Linux kernel thread daemon High (parent: Medium)
- A contained executable was executed by the Linux kernel thread daemon High (parent: Medium)
- A contained executable was executed by an unusual process Medium