Command and Scripting Interpreter: Container CLI/API T1059.013

Tactic: Execution

Adversaries may abuse built-in CLI tools or API calls to execute malicious commands in containerized environments.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (2 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine1contains 1, in 1 exec , * /bin/bash *, * /bin/dash *
process_name1starts_with 1docker

Top indicator values (14 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLinecontains
exec
13
CommandLinein
* /bin/bash *
1
CommandLinein
* /bin/dash *
1
CommandLinein
* /bin/sh *
1
CommandLinein
* /bin/zsh *
1
CommandLinein
* bash
1
CommandLinein
* bash *
1
CommandLinein
* dash
1
CommandLinein
* dash *
1
CommandLinein
* sh
1
CommandLinein
* sh *
1
CommandLinein
* zsh
1
CommandLinein
* zsh *
1
process_namestarts_with
docker
12

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Linux

Domain: Endpoint

Splunk 1 rule