kevmap

TechniquesT1046 › AN1060

AN1060 Analytic 1060

Containers · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects lateral discovery or container breakout attempts using netcat, curl, or custom binaries probing other services within the same namespace or VPC subnet.</p>
Detects
T1046 Network Service Discovery
Part of
DET0376 Behavioral Detection Strategy for Network Service Discovery Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
ebpf:syscallssocket connectDC0082 Network Connection Creation
ebpf:syscallsexecveDC0032 Process Creation
containerd:runtimecontainer-level outbound traffic eventsDC0078 Network Traffic Flow

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ExecutablePathCustom or renamed versions of tools may use different paths
TimeWindowAggregation interval for identifying anomalous traffic
NetworkDestinationCountTunable count of unique destinations to classify discovery

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2019-13608Citrix StoreFront ServerMapped
CVE-2021-21973VMware vCenter Server and Cloud FoundationMapped
CVE-2023-26360Adobe ColdFusionMapped
CVE-2023-38035Ivanti SentryMapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA GatewaysMapped
CVE-2025-32756Fortinet Multiple ProductsMapped