Analytics BIOC
Low
✕
Mount command was executed from within a Kubernetes pod to list all the attached filesystems
The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Escape to Host (T1611)
Detector tags: Kubernetes - AGENT
Attacker's goals:
Access to the host filesystem.
Investigative actions:
Look for additional suspicious activities. Verify if there was an attempt to access the host system.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unusual mount command was executed from within a Kubernetes pod to list all the attached filesystems Medium (parent: Low)