Analytics BIOC Informational

Suspicious process execution in a privileged container

A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002) Privilege Escalation (TA0004)
ATT&CK techniques: Container Administration Command (T1609) Escape to Host (T1611)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

Perform lateral movement to new hosts to expand the foothold within a network and gain higher privileges.

Investigative actions:

Investigate the processes being spawned on the host for malicious activities. Correlate the command run from the host and understand which software initiated it.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Suspicious process execution in a new privileged container Informational