Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0249 — Behavior-chain detection for T1610 Deploy Container across Docker & Kubernetes control/node planes
DET0249

Behavior-chain detection for T1610 Deploy Container across Docker & Kubernetes control/node planes

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0693 Analytic 0693
Containers

Remote/API driven creation **and** start of a container whose image is not on an allow‑list (or is tagged `latest`), executed by a non-admin principal, and/or started with risky runtime attributes (e.g., `--privileged`, host PID/NET namespaces, sensitive host path mounts, capability adds). Correlates *create* ➜ *start* ➜ first network/process actions from that container within a short time window.

docker:daemon container_create,container_start containerd:runtime CRI CreateContainer/StartContainer with privileged=true OR added capabilities OR host* namespaces ebpf:syscalls process execution or network connect from just-created container PID namespace docker:events remote API calls to /containers/create or /containers/{id}/start
[known_images] Environment-specific allow-list of approved images (with digests).
[known_admins] Service accounts or CI/CD users permitted to deploy containers.
[TimeWindow] Max time between create, start, and first activity to consider events causally linked (default 5m).
[RiskThreshold] Minimum number of risky attributes (e.g., unknown image + privileged) to alert.
[PrivilegedFlags] Set of runtime flags considered high risk (e.g., --privileged, --cap-add=SYS_ADMIN, hostPID, hostNetwork, /var/run/docker.sock mount).

Detected Techniques

1

Details

MITRE ID
DET0249
STIX ID
x-mitre-detection-strategy--994c7fc6-ad85-47e6-9079-fb872ec7e541
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.