{"id":"T1059.013","name":"Container CLI/API","url":"https://attack.mitre.org/techniques/T1059/013","tactics":["execution"],"platforms":["Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0083","stix_id":"x-mitre-detection-strategy--26580351-9bc3-4e03-b5ad-139d38303707","name":"Container CLI and API Abuse via Docker/Kubernetes (T1059.013)","url":"https://attack.mitre.org/detectionstrategies/DET0083","analytics":[{"id":"AN0233","stix_id":"x-mitre-analytic--e4dd4100-2387-4029-a478-35aefd37c288","name":"Analytic 0233","description":"Execution of container orchestration commands (e.g., `docker exec`, `kubectl exec`) or API-driven interactions with running containers from unauthorized hosts or non-standard user contexts. Defender sees programmatic or interactive command execution within containers outside expected CI/CD tools or automation frameworks, often followed by file writes, privilege escalation, or lateral discovery.","url":"https://attack.mitre.org/detectionstrategies/DET0083#AN0233","platforms":["Containers"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of container management CLIs (docker, crictl, kubectl) or interpreted shells (sh, bash, python) within container context","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"docker:events","channel":"exec_create: docker exec events targeting running containers from non-CI sources","data_component":"DC0077","data_component_name":"Container Start","log_source_slug":"docker-events"},{"name":"kubernetes:apiserver","channel":"create/exec: Kubernetes API calls to exec into containers or create pods from curl, kubectl, or SDK clients","data_component":"DC0072","data_component_name":"Container Creation","log_source_slug":"kubernetes-apiserver"},{"name":"AWS:CloudTrail","channel":"CreatePod: Programmatic creation of new pod resources using container images not seen before in the environment","data_component":"DC0019","data_component_name":"Pod Creation","log_source_slug":"aws-cloudtrail"},{"name":"kubernetes:audit","channel":"Shell process (e.g., /bin/sh, /bin/bash) spawned in a container without an interactive session attached (i.e., automation anomaly)","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"kubernetes-audit"}],"mutable_elements":[{"field":"AuthorizedUserAgents","description":"List of CI/CD pipeline runners, SRE tools, or cluster mgmt agents allowed to invoke API/CLI commands in containers."},{"field":"NewImageThreshold","description":"Threshold for alerting on unseen container images pulled and executed. Adjust to reduce noise from frequent deploys."},{"field":"TimeWindow","description":"Temporal window to correlate container exec with shell spawn and network activity (default: 2 minutes)."},{"field":"InteractiveSessionExpectation","description":"Set whether shell spawns without TTY or PTY should be flagged — based on org deployment model."}],"live":true,"detection_strategies":["DET0083"],"techniques":["T1059.013"]}],"live":true,"version":"1.0","techniques":["T1059.013"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}