{"id":"T1613","name":"Container and Resource Discovery","url":"https://attack.mitre.org/techniques/T1613","tactics":["discovery"],"platforms":["Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0490","stix_id":"x-mitre-detection-strategy--2f4449cb-0eec-4871-bff3-f846f12bec15","name":"Detection Strategy for Container and Resource Discovery","url":"https://attack.mitre.org/detectionstrategies/DET0490","analytics":[{"id":"AN1352","stix_id":"x-mitre-analytic--3947e311-cada-4eab-b4fd-1ea1f3fc3485","name":"Analytic 1352","description":"Detection of adversary attempts to enumerate containers, pods, nodes, and related resources within containerized environments. Defenders may observe anomalous API calls to Docker or Kubernetes (e.g., 'docker ps', 'kubectl get pods', 'kubectl get nodes'), unusual account activity against the Kubernetes dashboard, or unexpected queries against container metadata endpoints. These events should be correlated with user context and network activity to reveal resource discovery attempts.","url":"https://attack.mitre.org/detectionstrategies/DET0490#AN1352","platforms":["Containers"],"log_source_references":[{"name":"kubernetes:apiserver","channel":"list or get requests against pods, deployments, or nodes","data_component":"DC0037","data_component_name":"Pod Enumeration","log_source_slug":"kubernetes-apiserver"},{"name":"docker:daemon","channel":"docker ps, docker inspect, or docker images commands","data_component":"DC0091","data_component_name":"Container Enumeration","log_source_slug":"docker-daemon"}],"mutable_elements":[{"field":"UserAllowList","description":"Defines which service accounts and admin roles are expected to perform discovery actions. Activity by non-allowlisted identities may indicate adversary discovery."},{"field":"TimeWindow","description":"Specifies correlation period (e.g., 10m) for linking multiple discovery attempts across API and daemon logs."},{"field":"PodQueryThreshold","description":"Defines threshold for number of pod/node enumeration requests by a single user. Excessive queries may indicate scanning activity."}],"live":true,"detection_strategies":["DET0490"],"techniques":["T1613"]}],"live":true,"version":"1.0","techniques":["T1613"]}],"sigma_rules":[{"id":"597a7e84-187d-458b-9e4f-2f5a0e676711","title":"Kubernetes Potential Enumeration Activity","author":"uniqu3-us3r","status":"experimental","level":"medium","date":"2026-04-28","modified":null,"description":"Detects potential Kubernetes enumeration or attack activity via the audit log.\nThis includes the execution of common shells, utilities, or specialized tools like 'Rakkess' (access_matrix) and 'TruffleHog' via Kubernetes API requests.\nAttackers use these methods to perform reconnaissance (enumeration), secret harvesting, or execute code (exec) within a cluster.\n","references":["https://www.nccgroup.com/research/detection-engineering-for-kubernetes-clusters/","https://github.com/trufflesecurity/trufflehog","https://github.com/corneliusweig/rakkess"],"logsource":{"product":"kubernetes","service":"audit"},"tags":["attack.execution","attack.discovery","attack.t1609","attack.t1613"],"path":"rules/application/kubernetes/audit/kubernetes_audit_potential_enumeration_activity.yml","techniques":["T1609","T1613"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}