Analytics BIOC Informational

Suspicious process execution from tmp folder

An unpopular process was executed from the tmp folder.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Hide Artifacts: Hidden Files and Directories (T1564.001)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

Attackers may try to run the executable application from a folder that is writable to all users and use it to avoid detection.

Investigative actions:

Verify that this isn't IT activity. Look for other hosts executing similar commands.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • A web server process executed an unpopular application from the tmp folder Medium (parent: Informational)
  • Suspicious cron job task execution of a binary from the tmp folder Medium (parent: Informational)
  • Suspicious interactive execution of a binary from the tmp folder Medium (parent: Informational)
  • Suspicious process execution from tmp folder in a Kubernetes pod Informational