open-menu
closeme
Deprecated - AWS Credentials Searched For Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Credential Access
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Container Management Utility Run Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Execution
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Container Workload Protection
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - File Made Executable via Chmod Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Execution
Tactic: Defense Evasion
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - File System Debugger Launched Inside a Privileged Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Privilege Escalation
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Interactive Exec Command Launched Against A Running Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Execution
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Modification of Dynamic Linker Preload Shared Object Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
Tactic: Defense Evasion
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Mount Launched Inside a Privileged Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Privilege Escalation
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Netcat Listener Established Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Execution
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Potential Container Escape via Modified notify_on_release File
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Privilege Escalation
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Potential Container Escape via Modified release_agent File
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Privilege Escalation
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Sensitive Files Compression Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Collection
Tactic: Credential Access
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Sensitive Keys Or Passwords Searched For Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Credential Access
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - SSH Authorized Keys File Modified Inside a Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Persistence
Tactic: Lateral Movement
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - SSH Connection Established Inside A Running Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Initial Access
Tactic: Lateral Movement
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - SSH Process Launched From Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Lateral Movement
Tactic: Persistence
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Suspicious Interactive Shell Spawned From Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Execution
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
Deprecated - Suspicious Network Tool Launched Inside A Container
calendar
Mar 14, 2025
·
Data Source: Elastic Defend for Containers
Domain: Container
OS: Linux
Use Case: Threat Detection
Tactic: Discovery
Tactic: Command and Control
Tactic: Reconnaissance
Resources: Investigation Guide
·
Share on:
twitter
facebook
linkedin
copy
to-top