elastic
low
eql
Modification of Persistence Relevant Files Detected via Defend for Containers
This rule detects attempts from within a Linux container to create or modify files commonly used for
persistence on native Linux systems, including cron jobs, systemd units, sudoers files, and shell
profile configurations. While many of these mechanisms do not provide reliable persistence in typical
containerized workloads, such modifications are unusual and may indicate persistence attempts, privilege
abuse, or preparation for container escape, especially when performed outside normal image bui