Techniques › T1496 › AN0745
AN0745 Analytic 0745
Containers · attack.mitre.org · ATT&CK Enterprise v19.2
<p>High CPU usage by unauthorized containers running mining binaries or public proxy tools.</p>
- Detects
- T1496 Resource Hijacking
- Part of
- DET0267 Resource Hijacking Detection Strategy
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| containerd:events | New container with suspicious image name or high resource usage | DC0032 Process Creation |
| prometheus:metrics | Container CPU/Memory usage exceeding threshold | DC0018 Host Status |
| container:cni | Outbound network traffic to mining proxies | DC0078 Network Traffic Flow |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ImageName | Suspicious or unknown container image used |
CPUQuotaThreshold | Container-level resource limits |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | Mapped |
| CVE-2018-11776 | Apache Struts | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | Mapped |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | Mapped |
| CVE-2021-44228 | Apache Log4j2 | Mapped |
| CVE-2022-29303 | SolarView Compact | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | Mapped |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | Mapped |
| CVE-2023-32315 | Ignite Realtime Openfire | Mapped |
| CVE-2023-38035 | Ivanti Sentry | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | Mapped |