Analytics BIOC Informational

Suspicious container runtime connection from within a Kubernetes Pod

A process from within a Kubernetes Pod communicated with the container runtime daemon using the runtime socket. This may indicate an adversary attempting to escape from the Kubernetes Pod to the host.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Container Administration Command (T1609) Deploy Container (T1610)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

Escape from a container to the host machine and expand the foothold in the network.

Investigative actions:

Change the container socket configuration. Check if the default Docker daemon binding to TCP changed. If so, non-root users may gain access to the container.

Test period:
N/A (single event)
Deduplication:
5 Days
2 variations:
  • Suspicious container runtime connection from within a Kubernetes Pod using the curl client Low (parent: Informational)
  • Suspicious container runtime connection from within a Kubernetes Pod using the docker client Medium (parent: Informational)