Container Administration Command T1609

Tactic: Execution

Adversaries may abuse a container administration service to execute commands within a container. A container administration service such as the Docker daemon, the Kubernetes API server, or the kubelet may allow remote management of containers within an environment.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
ESFexecProcess Execution

Authoring guide

These 36 rules share fields, values, and exclusions.

Fields filtered most (40 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType26in 14, eq 12exec, exec_event, io.k8s.core.v1.pods.exec.create, io.k8s.core.v1.pods.exec.get, ProcessRollup2
event.type21eq 21start
host.os.type16eq 15, in 1
process_name16in 10, eq 7, starts_with 3bash, busybox, csh, ., crictl
process.args15in 10, eq 7, contains 5, starts_with 3, wildcard 2--mount, --net-host, --privileged, /bin/curl, /bin/kubectl
data_stream.dataset14eq 14gcp.audit, kubernetes.audit_logs, azure.platformlogs
container.id7wildcard 6, starts_with 1*, ?
kubernetes.audit.objectRef.subresource7eq 6, in 1exec, attach, ephemeralcontainers, log
ServiceName5eq 5k8s.io
event.outcome5eq 5success
kubernetes.audit.stage5in 4, eq 1ResponseComplete, ResponseStarted, responsecomplete
Esql.executed_command4is_not_null 4, regex_match 3.*(/var/run/secrets/|/etc/kubernetes/|/var/lib/kubelet/|/..., .*(169\.254\.169\.254|2852039166|0xa9fea9fe|/latest/api/t..., .*(curl.*https|wget.*https).*
gcp.audit.labels.command.gke.io/command4contains 3, wildcard 3*/etc/*.conf*, */home/*/.aws*, */home/*/.azure*, *IO*Socket*INET*, *bash*-i*
kubernetes.audit.annotations.authorization_k8s_io/decision4eq 4allow, forbid
kubernetes.audit.requestURI4contains 4command=

Top indicator values (434 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
211078
EventTypeeq
exec
9576
EventTypein
exec
8201
EventTypein
executed
798
EventTypein
exec_event
6149
EventTypein
start
6163
EventTypein
io.k8s.core.v1.pods.exec.create
55
EventTypein
io.k8s.core.v1.pods.exec.get
55
EventTypein
process_started
583
EventTypein
ProcessRollup2
4117
container.idwildcard
*
626
data_stream.dataseteq
gcp.audit
669
data_stream.dataseteq
kubernetes.audit_logs
536
ServiceNameeq
k8s.io
537
event.outcomeeq
success
5369
kubernetes.audit.objectRef.subresourceeq
exec
55
process.argseq
run
510
process_namein
bash
5202
process_namein
busybox
568
process_namein
csh
5159
process_namein
dash
5170
process_namein
fish
5163
process_namein
ksh
5163
process_namein
sh
5197
process_namein
tcsh
5156
process_namein
zsh
5196
kubernetes.audit.requestURIcontains
command=
44
kubernetes.audit.stagein
ResponseComplete
45
kubernetes.audit.stagein
ResponseStarted
45
process.interactiveeq
true
419

Exclusions (127 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
ParentImagein
/sbin/init
4
ParentImagein
/lib/systemd/systemd
2
ParentImagein
/usr/bin/containerd
2
ParentImagein
/usr/bin/containerd-shim-runc-v2
2
ParentImagein
/usr/bin/dockerd
2
ParentImagein
/usr/bin/kubelet
2
ParentImagein
/usr/bin/runc
2
ParentImagein
/usr/lib/systemd/systemd
2
ParentImagein
/usr/local/bin/kubelet
2
ParentImagein
/usr/sbin/containerd
2
azure.platformlogs.properties.log.user.usernameeq
aksservice
3
azure.platformlogs.properties.log.user.usernameeq
hcpservice
3
azure.platformlogs.properties.log.user.usernameeq
readinesschecker
3
azure.platformlogs.properties.log.user.usernamestarts_with
system:node:
3
CurrentDirectoryeq
/aws
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 33 rules