Analytics BIOC
Informational
✕
Suspicious curl user agent
Suspicious user agent provided to curl command.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol: Web Protocols (T1071.001)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:
Impairing host defenses.
Investigative actions:
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Suspicious curl user agent from within a Kubernetes Pod Low (parent: Informational)