Ciberseguridad desde Málaga · Redes, anzuelos y amenazas

← Amenazas
Técnica MITRE ATT&CK · Ejecución

T1059.013 Container CLI/API

Subtécnica de T1059 Command and Scripting Interpreter

Adversaries may abuse built-in CLI tools or API calls to execute malicious commands in containerized environments. The Docker CLI is used for managing containers via an exposed API point from the `dockerd` daemon. Some common examples of Docker CLI include Docker Desktop CLI and Docker Compose, but users are also able to use SDKs to interact with the API. For example, Docker SDK for Python can…

Ficha en MITRE ATT&CK ↗

Quién la usa · con noticias en Jábega

Reglas Sigma para cazarla

SigmaHQ no tiene reglas para esta técnica.

Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.