Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0473 — Detect persistent or elevated container services via container runtime or cluster manipulation
DET0473

Detect persistent or elevated container services via container runtime or cluster manipulation

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1304 Analytic 1304
Containers

Correlate the creation or modification of containers using restart policies (e.g., 'always') or DaemonSets with elevated host access, service account misuse, or privileged container contexts. Watch for manipulation of systemd units involving containers or pod scheduling targeting specific nodes or namespaces.

auditd:SYSCALL execve systemd:unit container run with restart policy set to 'always' or 'unless-stopped' kubernetes:audit create kubernetes:audit create
[restartPolicy] Tune for environments that legitimately use 'always' or 'unless-stopped' in trusted containers
[targetNamespace] Scope detection to high-risk namespaces (e.g., kube-system)
[nodeSelector|nodeName] Adjust if targeting known cluster configurations or test environments
[unitFilePath] Adapt to your OS/systemd hierarchy and container binary references
[TimeWindow] Adjust temporal correlation (e.g., container launch → privilege escalation)

Detected Techniques

1

Details

MITRE ID
DET0473
STIX ID
x-mitre-detection-strategy--81ac26e4-c4f6-4368-842f-50033ca8522b
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.