Analytics BIOC
Informational
✕
Kubernetes nsenter container escape
The nsenter command was used to execute a process in the context of the initialization process.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Escape to Host (T1611)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:
Attackers may break out of a container to run commands on the host.
Investigative actions:
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
- Test period:
- N/A (single event)
- Deduplication:
- 7 Days
2 variations:
- Kubernetes nsenter container escape from a new Pod Medium (parent: Informational)
- Kubernetes nsenter container escape from a Pod Low (parent: Informational)