Analytics BIOC Medium

A contained executable was executed by an unusual process

A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Escape to Host (T1611) Boot or Logon Autostart Execution: Kernel Modules and Extensions (T1547.006)
Attacker's goals:

Gain high privileged command execution on the host machine via one of its running containers.

Investigative actions:

Check what actions were made after the suspicious file execution. Investigate the contained process and its process tree.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • A contained executable was executed by the Linux kernel thread daemon High (parent: Medium)
  • A contained executable was executed by the Linux kernel thread daemon High (parent: Medium)
  • A contained executable was executed by an unusual process Medium