Techniques
Sample rules
Linux Suspicious Privileged Container Execution
- source: splunk
- technicques:
Description
The following analytic detects the execution of a Docker container with the privileged flag set, or with the pid namespace set to the host. This can indicate a container running with elevated permissions and access to the underlying system. Actors can hide containers such as this to enable persistent access.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime
max(_time) as lastTime
from datamodel=Endpoint.Processes where
Processes.process="*docker *"
Processes.process="* run*"
Processes.process IN ("*--privileged*", "*--pid=host*")
by Processes.process Processes.vendor_product Processes.user_id
Processes.process_hash Processes.parent_process_name
Processes.parent_process_exec Processes.action Processes.dest Processes.process_current_directory
Processes.process_path Processes.process_integrity_level Processes.original_file_name
Processes.parent_process Processes.parent_process_path Processes.parent_process_guid
Processes.parent_process_id Processes.process_guid Processes.process_id Processes.user
Processes.process_name
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_suspicious_privileged_container_execution_filter`