{"id":"T1543.005","name":"Container Service","url":"https://attack.mitre.org/techniques/T1543/005","tactics":["persistence","privilege-escalation"],"platforms":["Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0473","stix_id":"x-mitre-detection-strategy--81ac26e4-c4f6-4368-842f-50033ca8522b","name":"Detect persistent or elevated container services via container runtime or cluster manipulation","url":"https://attack.mitre.org/detectionstrategies/DET0473","analytics":[{"id":"AN1304","stix_id":"x-mitre-analytic--de64bfbd-a6ed-4674-b0c5-dd485cba943b","name":"Analytic 1304","description":"Correlate the creation or modification of containers using restart policies (e.g., 'always') or DaemonSets with elevated host access, service account misuse, or privileged container contexts. Watch for manipulation of systemd units involving containers or pod scheduling targeting specific nodes or namespaces.","url":"https://attack.mitre.org/detectionstrategies/DET0473#AN1304","platforms":["Containers"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"systemd:unit","channel":"container run with restart policy set to 'always' or 'unless-stopped'","data_component":"DC0072","data_component_name":"Container Creation","log_source_slug":"systemd-unit"},{"name":"kubernetes:audit","channel":"create","data_component":"DC0019","data_component_name":"Pod Creation","log_source_slug":"kubernetes-audit"},{"name":"kubernetes:audit","channel":"create","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"kubernetes-audit"}],"mutable_elements":[{"field":"restartPolicy","description":"Tune for environments that legitimately use 'always' or 'unless-stopped' in trusted containers"},{"field":"targetNamespace","description":"Scope detection to high-risk namespaces (e.g., kube-system)"},{"field":"nodeSelector|nodeName","description":"Adjust if targeting known cluster configurations or test environments"},{"field":"unitFilePath","description":"Adapt to your OS/systemd hierarchy and container binary references"},{"field":"TimeWindow","description":"Adjust temporal correlation (e.g., container launch → privilege escalation)"}],"live":true,"detection_strategies":["DET0473"],"techniques":["T1543.005"]}],"live":true,"version":"1.0","techniques":["T1543.005"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}