Log sources › docker:daemon
docker:daemon
Inverted view: what can be detected if this is the log you have. Containers
8
channels
8
analytics
8
techniques
6
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
ExecCreate + usermod or useradd |
DC0014 User Account Creation | AN1080 | 1 |
container create/start with privileged flag or host volume mount |
DC0072 Container Creation | AN0612 | 1 |
container file operations |
DC0040 File Deletion | AN0523 | 1 |
container_create,container_start |
DC0038 Application Log Content | AN0693 | 1 |
docker build or POST /build API request |
DC0015 Image Creation | AN1261 | 1 |
docker build or docker commit commands followed by docker push to internal registry |
DC0015 Image Creation | AN0946 | 1 |
docker exec or docker run with unexpected command/entrypoint |
DC0064 Command Execution | AN0177 | 1 |
docker ps, docker inspect, or docker images commands |
DC0091 Container Enumeration | AN1352 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1036.010 Masquerade Account Name | stealth | 0 | 0 |
| T1070 Indicator Removal | stealth | 20 | 3 |
| T1525 Implant Internal Image | persistence | 1 | 0 |
| T1609 Container Administration Command | execution | 3 | 0 |
| T1610 Deploy Container | execution | 0 | 0 |
| T1611 Escape to Host | privilege escalation | 2 | 3 |
| T1612 Build Image on Host | stealth | 0 | 0 |
| T1613 Container and Resource Discovery | discovery | 1 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2021-45382 | D-Link Multiple Routers | T1070 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1070 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1070 | Mapped |
| CVE-2025-22224 | VMware ESXi and Workstation | T1611 | Mapped |
| CVE-2025-22225 | VMware ESXi | T1611 | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | T1611 | Mapped |