Analytics BIOC Low

Mount command was executed from within a Kubernetes pod to list all the attached filesystems

The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Escape to Host (T1611)
Detector tags: Kubernetes - AGENT
Attacker's goals:

Access to the host filesystem.

Investigative actions:

Look for additional suspicious activities. Verify if there was an attempt to access the host system.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Unusual mount command was executed from within a Kubernetes pod to list all the attached filesystems Medium (parent: Low)