Analytics BIOC Informational

Suspicious docker image download from an unusual repository

The agent has pulled a docker image from a repository for the first time.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution: Malicious Image (T1204.003)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

Adversaries may rely on a user running a malicious image to facilitate execution.

Investigative actions:

Scan the docker image that was pulled. Check the repository designation. Check on which other agents the docker image is being used.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Suspicious docker image download from an unrecognized registry Low (parent: Informational)
  • Suspicious docker image download from an unrecognized repository Low (parent: Informational)