Analytics BIOC
Informational
✕
Suspicious process execution from tmp folder
An unpopular process was executed from the tmp folder.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Hide Artifacts: Hidden Files and Directories (T1564.001)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:
Attackers may try to run the executable application from a folder that is writable to all users and use it to avoid detection.
Investigative actions:
Verify that this isn't IT activity. Look for other hosts executing similar commands.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- A web server process executed an unpopular application from the tmp folder Medium (parent: Informational)
- Suspicious cron job task execution of a binary from the tmp folder Medium (parent: Informational)
- Suspicious interactive execution of a binary from the tmp folder Medium (parent: Informational)
- Suspicious process execution from tmp folder in a Kubernetes pod Informational