Loading interactive filters…
1200KM / detection
T1610 Deploy Container — Detection Rules
Detection workspace for T1610 Deploy Container: 0 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
T1610 Deploy Container
MATCH(workload_created) AND (image NOT_IN approved_images OR privileged = true OR host_mount = true) -> ALERT
Anomaly models
Privileged or long-running container workload deployed — T1610 Deploy Container
Comparison unit: deployer-image-namespace-runtime configuration.
Expected behavior: peer workloads use approved images and recurring privilege profiles.
Deviation: rare combination of privilege, image, mounts, identity, and namespace.
ATT&CK analytic guidance
Remote/API driven creation **and** start of a container whose image is not on an allow‑list (or is tagged `latest`), executed by a non-admin principal, and/or started with risky runtime attributes (e.g., `--privileged`, host PID/NET namespaces, sensitive host path mounts, capability adds). Correlates *create* ➜ *start* ➜ first network/process actions from that container within a short time window.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.