{"id":"T1204.003","name":"Malicious Image","url":"https://attack.mitre.org/techniques/T1204/003","tactics":["execution"],"platforms":["IaaS","Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0248","stix_id":"x-mitre-detection-strategy--ee7bd8ff-fbfd-4bb2-9d23-cf3f6ed342c7","name":"User Execution – Malicious Image (containers & IaaS) – pull/run → start → anomalous behavior (T1204.003)","url":"https://attack.mitre.org/detectionstrategies/DET0248","analytics":[{"id":"AN0691","stix_id":"x-mitre-analytic--4c16cebd-ac7e-472a-ae12-62966cbd19e2","name":"Analytic 0691","description":"CONTAINERS (Docker/K8s/containerd): A user pulls an untrusted image from a public/unknown registry and then creates/starts a container from that image. Shortly after start, the container spawns unexpected utilities (e.g., curl/wget/bash/python), or makes outbound network connections atypical for the namespace/workload. The analytic correlates Image Creation/Download → Container Creation → Container Start → Command Execution/Network activity within a short window and with a consistent image digest.","url":"https://attack.mitre.org/detectionstrategies/DET0248#AN0691","platforms":["Linux"],"log_source_references":[{"name":"containerd:events","channel":"Image pull from untrusted registry (name NOT IN allowlist) or new digest never seen before","data_component":"DC0015","data_component_name":"Image Creation","log_source_slug":"containerd-events"},{"name":"kubernetes:audit","channel":"create: Pod/Container created with image tag 'latest' or mutable tag; imagePullPolicy=Always; noDigest=true","data_component":"DC0072","data_component_name":"Container Creation","log_source_slug":"kubernetes-audit"},{"name":"kubernetes:events","channel":"start: ContainerStarted or Pulling image → Started container","data_component":"DC0077","data_component_name":"Container Start","log_source_slug":"kubernetes-events"},{"name":"auditd:SYSCALL","channel":"execve: Process in container namespace executes curl|wget|bash|sh|python|nc with outbound args","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"New egress from container IP/namespace to Internet or non-approved CIDRs/ASNs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ImageRegistryAllowList","description":"Approved registries/namespaces (e.g., ECR/GCR/ACR org repos)."},{"field":"TimeWindow","description":"Correlation window from image pull to container activity (e.g., ≤15m)."},{"field":"SuspiciousBinaries","description":"Executables treated as high-risk when run in app containers (bash, sh, curl, wget, nc, powershell for Windows containers)."},{"field":"NamespaceScope","description":"K8s namespaces that should never pull from Internet or run mutable tags."},{"field":"OutboundCIDRBlockList","description":"Destination networks/domains that should not be contacted by containers."}],"live":true,"detection_strategies":["DET0248"],"techniques":["T1204.003"]},{"id":"AN0692","stix_id":"x-mitre-analytic--7b711402-12f7-4985-93df-2693eaf9ebdb","name":"Analytic 0692","description":"IAAS (Cloud images/VMs): A new VM/instance is launched from a non-approved or newly-seen image (AMI/GCP Image/Azure Image). On first boot, cloud-init/user-data or embedded agents download code, spawn system utilities, or open outbound C2/mining traffic. The analytic correlates Instance/Image Creation → Instance Start → in-guest Process/Command Execution and/or anomalous network traffic.","url":"https://attack.mitre.org/detectionstrategies/DET0248#AN0692","platforms":["Windows"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"RunInstances","data_component":"DC0080","data_component_name":"Instance Start","log_source_slug":"aws-cloudtrail"},{"name":"azure:activity","channel":"Microsoft.Compute/virtualMachines/write: imageReference publisher NOT IN allowlist OR plan is new/unknown","data_component":"DC0076","data_component_name":"Instance Creation","log_source_slug":"azure-activity"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"New VM egress to crypto-mining pools or non-approved Internet ranges within minutes of boot","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ApprovedImageCatalog","description":"Set of golden images/owners and digest/IDs allowed to launch."},{"field":"UserDataInspection","description":"Whether to alert when userData/cloud-init contains exec or download directives."},{"field":"FirstBootWindow","description":"Time after start considered first-boot (e.g., ≤30m) for correlation."},{"field":"VMTagScope","description":"Restrict detection to prod or internet-facing subnets to reduce noise."}],"live":true,"detection_strategies":["DET0248"],"techniques":["T1204.003"]}],"live":true,"version":"1.0","techniques":["T1204.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}