Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0490 — Detection Strategy for Container and Resource Discovery
DET0490

Detection Strategy for Container and Resource Discovery

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1352 Analytic 1352
Containers

Detection of adversary attempts to enumerate containers, pods, nodes, and related resources within containerized environments. Defenders may observe anomalous API calls to Docker or Kubernetes (e.g., 'docker ps', 'kubectl get pods', 'kubectl get nodes'), unusual account activity against the Kubernetes dashboard, or unexpected queries against container metadata endpoints. These events should be correlated with user context and network activity to reveal resource discovery attempts.

kubernetes:apiserver list or get requests against pods, deployments, or nodes docker:daemon docker ps, docker inspect, or docker images commands
[UserAllowList] Defines which service accounts and admin roles are expected to perform discovery actions. Activity by non-allowlisted identities may indicate adversary discovery.
[TimeWindow] Specifies correlation period (e.g., 10m) for linking multiple discovery attempts across API and daemon logs.
[PodQueryThreshold] Defines threshold for number of pod/node enumeration requests by a single user. Excessive queries may indicate scanning activity.

Detected Techniques

1

Details

MITRE ID
DET0490
STIX ID
x-mitre-detection-strategy--2f4449cb-0eec-4871-bff3-f846f12bec15
Analytics
1
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.