Analytics BIOC
Informational
✕
Suspicious process execution in a privileged container
A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002) Privilege Escalation (TA0004)
ATT&CK techniques: Container Administration Command (T1609) Escape to Host (T1611)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:
Perform lateral movement to new hosts to expand the foothold within a network and gain higher privileges.
Investigative actions:
Investigate the processes being spawned on the host for malicious activities. Correlate the command run from the host and understand which software initiated it.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Suspicious process execution in a new privileged container Informational