{"id":"T1525","name":"Implant Internal Image","url":"https://attack.mitre.org/techniques/T1525","tactics":["persistence"],"platforms":["IaaS","Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0334","stix_id":"x-mitre-detection-strategy--c08df366-fa5a-4f34-a27e-b28e756f09f0","name":"Detection Strategy for T1525 – Implant Internal Image","url":"https://attack.mitre.org/detectionstrategies/DET0334","analytics":[{"id":"AN0946","stix_id":"x-mitre-analytic--de0a1136-1476-4c28-bf49-004ac3ef97f7","name":"Analytic 0946","description":"Implantation of malicious code into container images followed by registry push and use in new deployments.","url":"https://attack.mitre.org/detectionstrategies/DET0334#AN0946","platforms":["Containers"],"log_source_references":[{"name":"docker:daemon","channel":"docker build or docker commit commands followed by docker push to internal registry","data_component":"DC0015","data_component_name":"Image Creation","log_source_slug":"docker-daemon"},{"name":"docker:registry","channel":"push event of new image version from unrecognized user or context","data_component":"DC0036","data_component_name":"Image Modification","log_source_slug":"docker-registry"}],"mutable_elements":[{"field":"TimeWindow","description":"Time threshold between image creation and use in deployment – typically rapid in adversarial activity."},{"field":"UserContext","description":"The expected users or service accounts performing image pushes."},{"field":"RegistryNameRegex","description":"Expected naming patterns for trusted registries."}],"live":true,"detection_strategies":["DET0334"],"techniques":["T1525"]},{"id":"AN0947","stix_id":"x-mitre-analytic--7845facb-50f2-4d32-ae00-6766b9410681","name":"Analytic 0947","description":"Creation or modification of cloud virtual machine images (AMIs, custom images) with persistence mechanisms, followed by infrastructure provisioning that uses these implanted images.","url":"https://attack.mitre.org/detectionstrategies/DET0334#AN0947","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"RegisterImage","data_component":"DC0015","data_component_name":"Image Creation","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"ModifyImageAttribute","data_component":"DC0036","data_component_name":"Image Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"RunInstances","data_component":"DC0080","data_component_name":"Instance Start","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"IAMRole","description":"Roles that are allowed to register and modify images should be scoped narrowly."},{"field":"ImageTagRegex","description":"Expected tags or naming patterns for images (e.g., 'golden-image', 'base-image')."},{"field":"LaunchWindow","description":"Time interval between image creation and instance launch."}],"live":true,"detection_strategies":["DET0334"],"techniques":["T1525"]}],"live":true,"version":"1.0","techniques":["T1525"]}],"sigma_rules":[{"id":"b94bf91e-c2bf-4047-9c43-c6810f43baad","title":"AWS ECS Task Definition That Queries The Credential Endpoint","author":"Darin Smith","status":"test","level":"medium","date":"2022-06-07","modified":"2023-04-24","description":"Detects when an Elastic Container Service (ECS) Task Definition includes a command to query the credential endpoint.\nThis can indicate a potential adversary adding a backdoor to establish persistence or escalate privileges.\n","references":["https://github.com/RhinoSecurityLabs/pacu/blob/866376cd711666c775bbfcde0524c817f2c5b181/pacu/modules/ecs__backdoor_task_def/main.py","https://docs.aws.amazon.com/AmazonECS/latest/APIReference/API_RegisterTaskDefinition.html","https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task-iam-roles.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.persistence","attack.t1525"],"path":"rules/cloud/aws/cloudtrail/aws_ecs_task_definition_cred_endpoint_query.yml","techniques":["T1525"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}