Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
5 detectors match the current filters. technique: T1609 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Command execution in a Kubernetes pod Container administration commands were executed within a Kubernetes pod. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Remote code execution into Kubernetes Pod A container administration service was used to execute commands within a Kubernetes Pod. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious container runtime connection from within a Kubernetes Pod A process from within a Kubernetes Pod communicated with the container runtime daemon using the runtime socket. This may indicate an adversary attempting to escape from the Kubernetes Pod to the host. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. | Informational | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| Analytics BIOC | Unusual exec into a Kubernetes Pod An identity initiated a shell session within a Kubernetes pod using the exec command. The command allows an identity to establish a temporary shell session and execute commands in the pod. This may indicate an attacker attempting to gain an interactive shell, which will allow access to the pod's data. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |