kevmap

TechniquesT1036 › AN0358

AN0358 Analytic 0358

Containers · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary uses renamed container images, injects files into containers with misleading names or metadata (e.g., renamed system binaries), and executes them during startup or scheduled jobs.</p>
Detects
T1036 Masquerading
Part of
DET0127 Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
containerd:runtime/var/log/containers/*.logDC0032 Process Creation
docker:eventsdocker.events.jsonDC0028 Image Metadata
ebpf:syscallsfile_writeDC0061 File Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ImageLabelMismatchTune detection based on mismatch between image name and labels
StartupScriptLocationDetect binaries added or modified in startup path (e.g., /entrypoint.sh)
ProcessNamePatternAllow tuning based on suspicious binary naming inside containers

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-26500Veeam Backup & ReplicationMapped
CVE-2022-26501Veeam Backup & ReplicationMapped