Analytics BIOC
Low
✕
Kubernetes pod creation from unknown container image registry
A Kubernetes pod was created with a container image from an unknown registry.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Deploy Container (T1610)
Detector tags: Kubernetes - API
Attacker's goals:
Deploy container with a malicious image to facilitate execution.
Investigative actions:
Check the image registry designation in the organization. Scan the container image for any malicious components.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
1 variation:
- Kubernetes pod creation from unusual container image registry Low