LetsDefend Monitoring Alert

A Malicious Docker Container Executed

Feb, 19, 2024, 02:16 AM

Event ID: 228

Event Time: Feb, 19, 2024, 02:16 AM

Rule Name: SOC253 - A Malicious Docker Container Executed

Alert Type: Malware

MITRE Technique:
T1110 - Credential Access - Brute Force,
T1496 - Impact - Resource Hijacking,
T1133 - Initial Access - External Remote Services,
T1571 - Command and Control - Non-Standard Port,
T1059.004 - Execution - Command and Scripting Interpreter: Unix Shell,
T1610 - Execution - Deploy Container,
T1609 - Execution - Container Administration Command,
T1525 - Persistence - Implant Internal Image,

Severity: High

Incident Responder

2025 © LetsDefend

45305 Catalina ct. Suite 150, Sterling VA 20166