Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

12 detectors match the current filters. technique: T1611 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A contained executable from a mounted share initiated a suspicious outbound network connection A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical. Medium Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC A contained executable was executed by an unusual process A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical. Medium Platform Analytics XDR Agent Privilege Escalation, Persistence
Analytics BIOC Access to sensitive host files from within a Kubernetes pod A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. Informational Platform Analytics XDR Agent Privilege Escalation, Discovery
Analytics BIOC Kubernetes nsenter container escape The nsenter command was used to execute a process in the context of the initialization process. Informational Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Kubernetes Pod Created with host Inter Process Communications (IPC) namespace An identity created a Kubernetes pod with the host Inter Process Communications (IPC) namespace. This may indicate an adversary attempting to access data used by other pods that use the host's IPC namespace. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Pod created with host process ID (PID) namespace An identity created a Kubernetes pod with the host process ID (PID) namespace. This may indicate an adversary attempting to access processes running on the host, which could allow escalating privileges to root. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Pod Created With Sensitive Volume An identity created a Kubernetes Pod with a sensitive volume, allowing the Pod to have read or write permissions on the host's filesystem This could suggest an effort by an adversary to access sensitive files on the host and employ techniques for escalating privileges. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes pod creation with host network An identity created a Kubernetes pod attached to the host network. This may indicate an adversary attempting to access services bound to localhost, sniff traffic on any interface on the host, and potentially bypass the network policy. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Privileged Pod Creation An identity created a Kubernetes pod with a privileged container. This may indicate an adversary attempting to access that host's filesystem or gain root access to the host. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Mount command was executed from within a Kubernetes pod to list all the attached filesystems The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access. Low Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. Informational Platform Analytics XDR Agent Execution, Privilege Escalation