Analytics BIOC
Informational
✕
Suspicious docker image download from an unusual repository
The agent has pulled a docker image from a repository for the first time.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution: Malicious Image (T1204.003)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:
Adversaries may rely on a user running a malicious image to facilitate execution.
Investigative actions:
Scan the docker image that was pulled. Check the repository designation. Check on which other agents the docker image is being used.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Suspicious docker image download from an unrecognized registry Low (parent: Informational)
- Suspicious docker image download from an unrecognized repository Low (parent: Informational)