Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1609

T1609Container Administration Command

T1609 — Container Administration Command is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 5 detection use cases covering it and 4 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
5Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (5)

[LLM] Logging-operator Flow/Output CRD injects Fluentd @type exec block (CVE-2026-54680) Bespoke delivery · alerting SΣPDD [LLM] Fluentd aggregator pod spawns shell/curl via injected out_exec (CVE-2026-54680 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Lateral movement via aws ssm send-command or kubectl exec spawned by python/node Bespoke actions · alerting DSΣPDDCSCW [LLM] Kubernetes propagation via kubectl staged in /tmp (kubectl exec / get secrets) Bespoke actions · alerting DSΣPDDCS [LLM] Anonymous principal reaching kubelet/pod proxy subresources (CVE-2018-1002105 tunnel) Bespoke actions · alerting SΣPDDCW

Articles citing this technique (4)