Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1609

T1609Container Administration Command

T1609 — Container Administration Command is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 7 detection use cases covering it and 4 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
7Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (7)

[LLM] Fluentd config injection via Flow/Output CRD record_transformer (block-close + @type exec) Bespoke exploit · alerting SΣPDD [LLM] Fluentd aggregator pod spawns a shell (out_exec RCE execution) Bespoke install · alerting DSΣPDDCS [LLM] Fluentd aggregator pod reaches cloud IMDS 169.254.169.254 (credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Permissive RBAC grants create on logging-operator flows/outputs resources Bespoke delivery · hunting SΣPDD [LLM] Lateral movement via aws ssm send-command or kubectl exec spawned by python/node Bespoke actions · alerting DSΣPDDCSCW [LLM] Kubernetes propagation via kubectl staged in /tmp (kubectl exec / get secrets) Bespoke actions · alerting DSΣPDDCS [LLM] Anonymous principal reaching kubelet/pod proxy subresources (CVE-2018-1002105 tunnel) Bespoke actions · alerting SΣPDDCW

Articles citing this technique (4)