Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
8 detectors match the current filters. technique: T1611 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A contained executable from a mounted share initiated a suspicious outbound network connection A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | A contained executable was executed by an unusual process A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical. | Medium | Platform Analytics | XDR Agent | Privilege Escalation, Persistence |
| Analytics | A contained process attempted to escape using the 'notify on release' feature A contained process attempted to escape the host by leveraging the Docker's 'notify on release' feature. The calling process modified relevant files that might trigger a command on the host. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Access to sensitive host files from within a Kubernetes pod A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. | Informational | Platform Analytics | XDR Agent | Privilege Escalation, Discovery |
| Analytics BIOC | Kubernetes nsenter container escape The nsenter command was used to execute a process in the context of the initialization process. | Informational | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | Mount command was executed from within a Kubernetes pod to list all the attached filesystems The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access. | Low | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. | Informational | Platform Analytics | XDR Agent | Execution, Privilege Escalation |