This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Privileged Container Deployed
Original Source:
[Sigma source]
Title:
Privileged Container Deployed
Status:
test
Description:
Detects the creation of a "privileged" container, an action which could be indicative of a threat actor mounting a container breakout attacks. A privileged container is a container that can access the host with all of the root capabilities of the host machine. This allows it to view, interact and modify processes, network operations, IPC calls, the file system, mount points, SELinux configurations etc. as the root user on the host. Various versions of "privileged" containers can be specified, e.g. by setting the securityContext.privileged flag in the resource specification, setting non-standard Linux capabilities, or configuring the hostNetwork/hostPID fields
References:
-https://microsoft.github.io/Threat-Matrix-for-Kubernetes/techniques/Privileged%20container/
-https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-kubernetes.html#privilegeescalation-kubernetes-privilegedcontainer
-https://www.elastic.co/guide/en/security/current/kubernetes-pod-created-with-hostnetwork.html
-https://www.elastic.co/guide/en/security/current/kubernetes-container-created-with-excessive-linux-capabilities.html
Author:
Leo Tsaousis (@laripping)
Date:
2024-03-26
modified:
None
Tags:
-'attack.t1611'
-'attack.privilege-escalation'
Logsource:
category: application
product: kubernetes
service: audit
Detection:
selection:
verb
:
'create'
objectRef.resource
:
'pods'
capabilities
:
'*'
condition
:
selection
Falsepositives:
-Unknown
Level:
low