kevmap

TechniquesT1036.005 › AN0986

AN0986 Analytic 0986

Containers · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects malicious containers or pods using names, labels, or namespaces that mimic legitimate workloads; also checks for image layer mismatches and unauthorized resource deployments.</p>
Detects
T1036.005 Match Legitimate Resource Name or Location
Part of
DET0347 Detection Strategy for Masquerading via Legitimate Resource Name or Location

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
kubernetes:apiserverResource creation and update logsDC0028 Image Metadata
containerd:eventsDocker or containerd image pulls and process executionsDC0034 Process Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
trusted_namespace_listList of namespaces that should not be used by unprivileged users or workloads
image_baseline_hashesReference hashes of approved container images

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2023-26360Adobe ColdFusionMapped