Sub-technique of T1204 User Execution.View on attack.mitre.org
Adversaries may rely on a user running a malicious image to facilitate execution. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker can be backdoored. Backdoored images may be uploaded to a public repository via Upload Malware, and users may then download and deploy an instance or container from the image without realizing the image is malicious, thus bypassing techniques that specifically achieve Initial Access. This can lead to the execution of malicious code, such as code that executes cryptocurrency mining, in the instance or container.
Adversaries may also name images a certain way to increase the chance of users mistakenly deploying an instance or container from the image (ex: Match Legitimate Resource Name or Location).
Rules on DetectionCode tagged with T1204.003.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ASL AWS ECR Container Upload Outside Business Hours | Anomaly | NULL | ASL AWS CloudTrail |
| ASL AWS ECR Container Upload Unknown User | Anomaly | NULL | ASL AWS CloudTrail |
| AWS ECR Container Scanning Findings High | TTP | NULL | AWS CloudTrail DescribeImageScanFindings |
| AWS ECR Container Scanning Findings Low Informational Unknown | Anomaly | NULL | AWS CloudTrail DescribeImageScanFindings |
| AWS ECR Container Scanning Findings Medium | Anomaly | NULL | AWS CloudTrail DescribeImageScanFindings |
| AWS ECR Container Upload Outside Business Hours | Anomaly | NULL | AWS CloudTrail PutImage |
| AWS ECR Container Upload Unknown User | Anomaly | NULL | AWS CloudTrail PutImage |
| Cisco Isovalent - Non Allowlisted Image Use | Anomaly | NULL | Cisco Isovalent Process Exec |
| Cisco Isovalent - Pods Running Offensive Tools | Anomaly | NULL | Cisco Isovalent Process Exec |
| Correlation by Repository and Risk | Correlation | NULL | |
| Correlation by User and Risk | Correlation | NULL | |
| Risk Rule for Dev Sec Ops by Repository | Correlation | NULL |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.