Log sources › containerd:Events
containerd:Events
Inverted view: what can be detected if this is the log you have. Containers, Linux
5
channels
5
analytics
5
techniques
24
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Docker or containerd image pulls and process executions |
DC0034 Process Metadata | AN0986 | 1 |
Image pull from untrusted registry (name NOT IN allowlist) or new digest never seen before |
DC0015 Image Creation | AN0691 | 1 |
New container with suspicious image name or high resource usage |
DC0032 Process Creation | AN0745 | 1 |
create |
DC0072 Container Creation | AN1492 | 1 |
unusual process spawned from container image context |
DC0032 Process Creation | AN1158 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location | stealth | 21 | 1 |
| T1204.003 Malicious Image | execution | 0 | 0 |
| T1496 Resource Hijacking | impact | 13 | 19 |
| T1496.001 Compute Hijacking | impact | 0 | 0 |
| T1552 Unsecured Credentials | credential access | 13 | 4 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1496 | Mapped |
| CVE-2018-11776 | Apache Struts | T1496 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1496 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1496 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1552 | Stale |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1496 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1496 | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | T1496 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1496 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1496 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1496 | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | T1496 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1496 | Mapped |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | T1496 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1036.005 | Mapped |
| CVE-2023-32315 | Ignite Realtime Openfire | T1496 | Mapped |
| CVE-2023-38035 | Ivanti Sentry | T1496 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1496 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1552 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1496 | Mapped |
| CVE-2024-20439 | Cisco Smart Licensing Utility | T1552 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1552 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1496 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1496 | Mapped |