Analytics BIOC
Informational
✕
Permission Groups discovery commands
Permission group discovery command execution.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Permission Groups Discovery: Local Groups (T1069.001)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:
Collect information about the host.
Investigative actions:
Verify if the script or process initiating the discovery commands is benign. Verify that this isn't sanctioned IT activity. Look for other hosts executing similar commands.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Permission Groups discovery commands in a Kubernetes pod Informational