kevmap

TechniquesT1133 › AN1007

AN1007 Analytic 1007

Containers · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Connections to exposed container services (e.g., Docker API, Kubernetes API server) from unauthorized external IPs → abnormal container creation/start → lateral activity within cluster nodes.</p>
Detects
T1133 External Remote Services
Part of
DET0354 Behavior-chain detection for T1133 External Remote Services across Windows, Linux, macOS, Containers

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
ApplicationLog:APIDocker/Kubernetes API access from external sourcesDC0038 Application Log Content
kubernetes:auditUnauthorized container creation or kubelet exec logsDC0088 Logon Session Metadata
NSM:FlowExternal access to container ports (2375, 6443)DC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AllowedCIDRsApproved external IP ranges for container APIs.
TimeWindowCorrelation window for API calls and container starts.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2014-6271GNU Bourne-Again Shell (Bash)Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash)Mapped
CVE-2018-4939Adobe ColdFusionMapped
CVE-2019-0708Microsoft Remote Desktop ServicesMapped
CVE-2019-11510Ivanti Pulse Connect SecureMapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceMapped
CVE-2019-3396Atlassian Confluence Server and Data ServerMapped
CVE-2019-5591Fortinet FortiOSMapped
CVE-2020-1472Microsoft NetlogonMapped
CVE-2020-25506D-Link DNS-320 DeviceMapped
CVE-2020-5902F5 BIG-IPStale
CVE-2020-8515DrayTek Multiple Vigor RoutersMapped
CVE-2021-1497Cisco HyperFlex HXMapped
CVE-2021-1498Cisco HyperFlex HXMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26855Microsoft Exchange ServerMapped
CVE-2021-26857Microsoft Exchange ServerMapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat DefenseMapped
CVE-2023-27532Veeam Backup & ReplicationMapped
CVE-2023-39780ASUS RT-AX55 RoutersMapped
CVE-2023-48365Qlik SenseMapped
CVE-2024-11120GeoVision Multiple DevicesMapped
CVE-2024-45195Apache OFBizMapped
CVE-2025-32756Fortinet Multiple ProductsMapped