Potential Remote Command Execution In Pod Container

Rule Info

Name
Potential Remote Command Execution In Pod Container
Author
Leo Tsaousis (@laripping)
Description
Detects attempts to execute remote commands, within a Pod's container using e.g. the "kubectl exec" command.
Date
2024-03-26 00:00:00
Modified
None
Id
a1b0ca4e-7835-413e-8471-3ff2b8a66be6
Tags
attack.t1609 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Leo Tsaousis
Merge PR #4694 from @LAripping - Add native Kubernetes detections
2024-03-26