Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1610

T1610Deploy Container

T1610 — Deploy Container is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 9 detection use cases covering it and 8 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
9Use cases
8Articles
0Sub-techniques
1Tactic

Use cases covering this technique (9)

[WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [LLM] Rancher /v3/import authImage YAML injection via URL-encoded newlines (CVE-2026-44939) Bespoke exploit · alerting SΣP [LLM] kubectl apply of attacker-crafted Rancher import URL (authImage payload delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] Fission Environment CRD create/update with dangerous SecurityContext on standalone container (CVE-2026-50566) Bespoke exploit · alerting SΣPDD [LLM] Privileged / dangerous-capability pod scheduled in Fission function/builder namespace by executor SA Bespoke install · alerting SPDD [LLM] Docker / Kubernetes pull of compromised ghcr.io/elementary-data/elementary image Bespoke delivery · alerting DSΣPDDCS [LLM] Kubernetes privileged-pod DaemonSet fan-out from compromised LiteLLM workload Bespoke actions · hunting SPDD [LLM] Malicious privileged DaemonSet apply in kube-system (host-provisioner-iran / host-provisioner-std / kamikaze) Bespoke install · alerting DSΣPDDCS [LLM] Host runc binary overwrite from container (CVE-2019-5736 escape-to-host) Bespoke install · alerting DSΣPCS

Articles citing this technique (8)