Container Residence Discovery Via Proc Virtual FS

Rule Info

Name
Container Residence Discovery Via Proc Virtual FS
Author
Seth Hanford
Description
Detects potential container discovery via listing of certain kernel features in the "/proc" virtual filesystem
Date
2023-08-23 00:00:00
Modified
None
Id
746c86fb-ccda-4816-8997-01386263acc4
Tags
attack.discovery attack.t1082 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
SethHanford
Merge PR #4380 from @SethHanford - Lnx container discovery
2023-08-24