Title:
Potential Container Discovery Via Inodes Listing
Status:
test
Description:Detects listing of the inodes of the "/" directory to determine if the we are running inside of a container.
References:
-https://blog.skyplabs.net/posts/container-detection/
-https://stackoverflow.com/questions/20010199/how-to-determine-if-a-process-runs-inside-lxc-docker
Author: Seth Hanford
Date: 2023-08-23
modified:2025-11-24
Tags:
- -'attack.discovery'
- -'attack.t1082'
Logsource:
- category: process_creation
- product: linux
Detection:
selection_ls_img:
Image|endswith:
'/ls'
selection_ls_cli:
CommandLine|endswith:
' /'
CommandLine|contains:
' / '
selection_regex_inode:
CommandLine|re:
'(?:\s-[^-\s]{0,20}i|\s--inode\s)'
selection_regex_dir:
CommandLine|re:
'(?:\s-[^-\s]{0,20}d|\s--directory\s)'
condition:
all of selection_*
Falsepositives:
-Legitimate system administrator usage of these commands
-Some container tools or deployments may use these techniques natively to determine how they proceed with execution, and will need to be filtered
Level:
low