Techniques › T1496.001 › AN1492
AN1492 Analytic 1492
Containers · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Ephemeral or unauthorized container instantiation using public images (e.g., from DockerHub) that initiate high CPU usage shortly after startup. Often scheduled via Kubernetes or Docker socket abuse.</p>
- Detects
- T1496.001 Compute Hijacking
- Part of
- DET0540 Multi-Platform Behavioral Detection for Compute Hijacking
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| containerd:events | create | DC0072 Container Creation |
| auditd:SYSCALL | execve | DC0032 Process Creation |
| NSM:Flow | Outbound traffic to mining pool upon container launch | DC0078 Network Traffic Flow |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ImageSource | May vary depending on where the image is pulled from (registry or custom URL). |
Namespace | Helps differentiate attacker-created namespaces. |