Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0083 — Container CLI and API Abuse via Docker/Kubernetes (T1059.013)
DET0083

Container CLI and API Abuse via Docker/Kubernetes (T1059.013)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0233 Analytic 0233
Containers

Execution of container orchestration commands (e.g., `docker exec`, `kubectl exec`) or API-driven interactions with running containers from unauthorized hosts or non-standard user contexts. Defender sees programmatic or interactive command execution within containers outside expected CI/CD tools or automation frameworks, often followed by file writes, privilege escalation, or lateral discovery.

auditd:SYSCALL execve: Execution of container management CLIs (docker, crictl, kubectl) or interpreted shells (sh, bash, python) within container context docker:events exec_create: docker exec events targeting running containers from non-CI sources kubernetes:apiserver create/exec: Kubernetes API calls to exec into containers or create pods from curl, kubectl, or SDK clients AWS:CloudTrail CreatePod: Programmatic creation of new pod resources using container images not seen before in the environment kubernetes:audit Shell process (e.g., /bin/sh, /bin/bash) spawned in a container without an interactive session attached (i.e., automation anomaly)
[AuthorizedUserAgents] List of CI/CD pipeline runners, SRE tools, or cluster mgmt agents allowed to invoke API/CLI commands in containers.
[NewImageThreshold] Threshold for alerting on unseen container images pulled and executed. Adjust to reduce noise from frequent deploys.
[TimeWindow] Temporal window to correlate container exec with shell spawn and network activity (default: 2 minutes).
[InteractiveSessionExpectation] Set whether shell spawns without TTY or PTY should be flagged — based on org deployment model.

Detected Techniques

1

Details

MITRE ID
DET0083
STIX ID
x-mitre-detection-strategy--26580351-9bc3-4e03-b5ad-139d38303707
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.