T1610 – Deploy Container (Prisma Cloud Detection)
Prisma Cloud Alert Details Alert ID: PRISMA-DEPLOY-CONTAINER-1610-7842 Alert Time: 2024-02-13 09:15:33 EST Severity: HIGH (82/100) Source: Prisma Cloud Compute Rule: “Unauthorized Container Deployment – Crypto Mining” MITRE ATT&CK: T1610 – Deploy Container Alert Details: Detection: Unauthorized container deployed in Kubernetes cluster Cluster: dev-eks-cluster-02 Namespace: default (unauthorized namespace) Image: docker.io/monero/xmrig:latest Container Name: kube-system-worker (masquerading as system … Read more