kevmap

TechniquesT1685 › AN1373

AN1373 Analytic 1373

Containers · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects disabling container runtime security controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or killing in-container monitoring agents.</p>
Detects
T1685 Disable or Modify Tools
Part of
DET0497 Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
kubernetes:auditkubectl delete or patch of security pods/admission controllersDC0041 Service Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
NamespaceExclusionsExclusion of namespaces where temporary deletion of monitoring tools is legitimate (e.g., staging).