User Execution: Malicious Image T1204.003
Tactic: Execution
Adversaries may rely on a user running a malicious image to facilitate execution. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker can be backdoored. Backdoored images may be uploaded to a public repository via Upload Malware, and users may then download and deploy an instance or container from the image without realizing the image is malicious, thus bypassing techniques that specifically achieve Initial Access. This can lead to the execution of malicious code, such as code that executes cryptocurrency mining, in the instance or container.
Authoring guide
These 10 rules share fields, values, and exclusions.
Fields filtered most (12 distinct)
These fields appear most often in rule filters.
Top indicator values (87 distinct)
These values appear most often in rule predicates.
Exclusions (7 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Splunk 10 rules
- ASL AWS ECR Container Upload Outside Business Hours
- ASL AWS ECR Container Upload Unknown User
- AWS ECR Container Scanning Findings High
- AWS ECR Container Scanning Findings Low Informational Unknown
- AWS ECR Container Scanning Findings Medium
- AWS ECR Container Upload Outside Business Hours
- AWS ECR Container Upload Unknown User
- Cisco Isovalent - Non Allowlisted Image Use
- Cisco Isovalent - Pods Running Offensive Tools
- Risk Rule for Dev Sec Ops by Repository