Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0459 — Detection Strategy for Build Image on Host
DET0459

Detection Strategy for Build Image on Host

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1261 Analytic 1261
Containers

Detection of container image build activity directly on the host using Docker or Kubernetes APIs. Defenders may observe Docker build requests, anomalous Dockerfile instructions (such as downloading code from unknown IPs), or creation of new images followed by immediate deployment. This behavior chain typically consists of an unexpected image creation event correlated with outbound network communication to non-standard or untrusted destinations.

docker:daemon docker build or POST /build API request NSM:Flow outbound connections from host during or immediately after image build
[RegistryAllowList] Defines trusted registries for image pulls/builds. Builds referencing unapproved registries may indicate adversary behavior.
[NewImageThreshold] Threshold for number of new custom images created in a given time window. Exceeding this threshold may indicate malicious builds.
[TimeWindow] Defines correlation window (e.g., 5m) between suspicious build activity and subsequent network traffic anomalies.

Detected Techniques

1

Details

MITRE ID
DET0459
STIX ID
x-mitre-detection-strategy--62b445ed-7d9d-4c1a-8d4e-6c742ec1b0e2
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.