Analytics BIOC
Informational
✕
Suspicious container runtime connection from within a Kubernetes Pod
A process from within a Kubernetes Pod communicated with the container runtime daemon using the runtime socket. This may indicate an adversary attempting to escape from the Kubernetes Pod to the host.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Container Administration Command (T1609) Deploy Container (T1610)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:
Escape from a container to the host machine and expand the foothold in the network.
Investigative actions:
Change the container socket configuration. Check if the default Docker daemon binding to TCP changed. If so, non-root users may gain access to the container.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
2 variations:
- Suspicious container runtime connection from within a Kubernetes Pod using the curl client Low (parent: Informational)
- Suspicious container runtime connection from within a Kubernetes Pod using the docker client Medium (parent: Informational)