Browse Rules

Search and filter across all detection sources

2,075 rules

elastic low eql

Container Management Utility Execution Detected via Defend for Containers

This rule detects when a container management binary is run from inside a container. These binaries are critical components of many containerized environments, and their presence and execution in unauthorized containers could indicate compromise or a misconfiguration.

elastic low eql

Container Management Utility Run Inside A Container

This rule detects when a container management binary is run from inside a container. These binaries are critical components of many containerized environments, and their presence and execution in unauthorized containers could indicate compromise or a misconfiguration.

falco high other

Detect release_agent File Container Escapes

Detect an attempt to exploit a container escape using release_agent file. By running a container with certains capabilities, a privileged user can modify release_agent file and escape from the container.

falco low other

Debugfs Launched in Privileged Container

Detect file system debugger debugfs launched inside a privileged container which might lead to container escape. This rule has a more narrow scope.

sagan medium other

[CISCO-PRIME] Rogue ADHOC contained

[CISCO-PRIME] Rogue ADHOC contained

sagan medium other

[CISCO-PRIME] Rogue auto contained

[CISCO-PRIME] Rogue auto contained

sagan medium other

[CISCO-PRIME] Rogue detected contained

[CISCO-PRIME] Rogue detected contained

falco low other

Container Run as Root User

Container detected running as the root user. This should be taken into account especially when policies disallow containers from running with root user privileges. Note that a root user in containers doesn't inherently possess extensive power, as modern container environments define privileges through Linux capabilities. To learn more, check out the rule "Launch Privileged Container".

falco low other

Modify Container Entrypoint

This rule detect an attempt to write on container entrypoint symlink (/proc/self/exe). Possible CVE-2019-5736 Container Breakout exploitation attempt. This rule has a more narrow scope.

sagan medium other

[CISCO-PRIME] Rogue AP auto contained

[CISCO-PRIME] Rogue AP auto contained

signature-base unknown yara

ACE_Containing_EXE [yara]

Looks for ACE Archives containing an exe/scr file

wazuh informational xml

Docker: Container $(docker.Actor.Attributes.name) started

Docker: Container $(docker.Actor.Attributes.name) started

wazuh informational xml

Docker: Container $(docker.Actor.Attributes.name) stopped

Docker: Container $(docker.Actor.Attributes.name) stopped

wazuh informational xml

Docker: Container $(docker.Actor.Attributes.name) paused

Docker: Container $(docker.Actor.Attributes.name) paused

wazuh informational xml

Docker: Container $(docker.Actor.Attributes.name) unpaused

Docker: Container $(docker.Actor.Attributes.name) unpaused

wazuh informational xml

Docker: Container $(docker.Actor.Attributes.name) restarted

Docker: Container $(docker.Actor.Attributes.name) restarted

falco medium other

Launch Package Management Process in Container

Detect package management processes executed within containers. An excellent auditing rule to monitor general drifts in containers. Particularly useful for newer rules like "Drop and execute new binary in container" during incident response investigations. This helps identify common anti-patterns of ad-hoc debugging. Simultaneously, to maintain optimal hygiene, it's recommended to prevent container drifts and instead opt for redeploying new containers.

sagan high other

[CITRIX] Netscaler - Message contains SOAP Fault

[CITRIX] Netscaler - Message contains SOAP Fault

sigma low sigma

Azure Container Registry Created or Deleted

Detects when a Container Registry is created or deleted.

elastic low eql

Exec Into Container Detected via Defend for Containers

This rule detects 'exec' events launched against a container using the 'exec' command. Using the 'exec' command in a pod allows a user to establish a temporary shell session and execute any process/command inside the container. This rule specifically targets higher-risk commands that allow real-time interaction with a container's shell. A malicious actor could use this level of access to further compromise the container environment or attempt a container breakout.

elastic low eql

Process Killing Detected via Defend for Containers

This rule detects the killing of processes inside a container. An adversary may attempt to find and kill competing processes to gain control of the container.

elastic medium kql

Container Workload Protection

Generates a detection alert each time a 'Container Workload Protection' alert is received. Enabling this rule allows you to immediately begin triaging and investigating these alerts.

falco low other

Launch Excessively Capable Container

Identify containers that start with a powerful set of capabilities, with exceptions for recognized trusted images. Similar to the "Launch Privileged Container" rule, this functions as a robust auditing rule. Compromised highly privileged containers can lead to substantial harm. For instance, if another rule is triggered within such a container, it might raise suspicion, prompting closer scrutiny.

elastic medium eql

Sensitive File Compression Detected via Defend for Containers

Identifies the use of a compression utility to collect known files containing sensitive information, such as credentials and system configurations inside a container.

sagan medium other

[CISCO-PRIME] Malicious rogue AP detected contained

[CISCO-PRIME] Malicious rogue AP detected contained