Container Service

T1543.005

Sub-technique of T1543 Create or Modify System Process.View on attack.mitre.org

About this technique

Adversaries may create or modify container or container cluster management tools that run as daemons, agents, or services on individual hosts. These include software for creating and managing individual containers, such as Docker and Podman, as well as container cluster node-level agents such as kubelet. By modifying these services, an adversary may be able to achieve persistence or escalate their privileges on a host.

For example, by using the `docker run` or `podman run` command with the `restart=always` directive, a container can be configured to persistently restart on the host. A user with access to the (rootful) docker command may also be able to escalate their privileges on the host.

In Kubernetes environments, DaemonSets allow an adversary to persistently Deploy Containers on all nodes, including ones added later to the cluster. Pods can also be deployed to specific nodes using the `nodeSelector` or `nodeName` fields in the pod spec.

Note that containers can also be configured to run as Systemd Services.

Detection rules0

Rules on DetectionCode tagged with T1543.005.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References8

  1. AppSecco Kubernetes Namespace Breakout 2020 Open source
    Abhisek Datta. (2020, March 18). Kubernetes Namespace Breakout using Insecure Host Path Volume — Part 1. Retrieved January 16, 2024.
  2. AquaSec TeamTNT 2023 Open source
    Ofek Itach and Assaf Morag. (2023, July 13). TeamTNT Reemerged with New Aggressive Cloud Campaign. Retrieved February 15, 2024.
  3. Aquasec Kubernetes Attack 2023 Open source
    Michael Katchinskiy, Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved July 14, 2023.
  4. Docker Systemd Open source
    Docker. (n.d.). Start containers automatically. Retrieved February 15, 2024.
  5. GTFOBins Docker Open source
    GTFOBins. (n.d.). docker. Retrieved February 15, 2024.
  6. Kubernetes Assigning Pods to Nodes Open source
    Kubernetes. (n.d.). Assigning Pods to Nodes. Retrieved February 15, 2024.
  7. Kubernetes DaemonSet Open source
    Kubernetes. (n.d.). DaemonSet. Retrieved February 15, 2024.
  8. Podman Systemd Open source
    Valentin Rothberg. (2022, March 16). How to run pods as systemd services with Podman. Retrieved February 15, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.