{"id":"T1610","name":"Deploy Container","url":"https://attack.mitre.org/techniques/T1610","tactics":["execution"],"platforms":["Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0249","stix_id":"x-mitre-detection-strategy--994c7fc6-ad85-47e6-9079-fb872ec7e541","name":"Behavior-chain detection for T1610 Deploy Container across Docker & Kubernetes control/node planes","url":"https://attack.mitre.org/detectionstrategies/DET0249","analytics":[{"id":"AN0693","stix_id":"x-mitre-analytic--c345908d-4f74-4341-a203-8c76be2a136b","name":"Analytic 0693","description":"Remote/API driven creation **and** start of a container whose image is not on an allow‑list (or is tagged `latest`), executed by a non-admin principal, and/or started with risky runtime attributes (e.g., `--privileged`, host PID/NET namespaces, sensitive host path mounts, capability adds). Correlates *create* ➜ *start* ➜ first network/process actions from that container within a short time window.","url":"https://attack.mitre.org/detectionstrategies/DET0249#AN0693","platforms":["Containers"],"log_source_references":[{"name":"docker:daemon","channel":"container_create,container_start","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"docker-daemon"},{"name":"containerd:runtime","channel":"CRI CreateContainer/StartContainer with privileged=true OR added capabilities OR host* namespaces","data_component":"DC0077","data_component_name":"Container Start","log_source_slug":"containerd-runtime"},{"name":"ebpf:syscalls","channel":"process execution or network connect from just-created container PID namespace","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"ebpf-syscalls"},{"name":"docker:events","channel":"remote API calls to /containers/create or /containers/{id}/start","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"docker-events"}],"mutable_elements":[{"field":"known_images","description":"Environment-specific allow-list of approved images (with digests)."},{"field":"known_admins","description":"Service accounts or CI/CD users permitted to deploy containers."},{"field":"TimeWindow","description":"Max time between create, start, and first activity to consider events causally linked (default 5m)."},{"field":"RiskThreshold","description":"Minimum number of risky attributes (e.g., unknown image + privileged) to alert."},{"field":"PrivilegedFlags","description":"Set of runtime flags considered high risk (e.g., --privileged, --cap-add=SYS_ADMIN, hostPID, hostNetwork, /var/run/docker.sock mount)."}],"live":true,"detection_strategies":["DET0249"],"techniques":["T1610"]}],"live":true,"version":"1.0","techniques":["T1610"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}