1200KM / detection
T1613 Container and Resource Discovery — Detection Rules
Detection workspace for T1613 Container and Resource Discovery: 1 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Kubernetes Potential Enumeration Activity · experimental · medium · {"product":"kubernetes","service":"audit"}
Atlas deterministic concepts
T1613 Container and Resource Discovery
COUNT(orchestrator_list_or_get_requests BY identity, 5m) >= threshold AND identity NOT_IN approved_cluster_admins -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0490 Detection Strategy for Container and Resource Discovery
AN1352 Analytic 1352
Detection of adversary attempts to enumerate containers, pods, nodes, and related resources within containerized environments. Defenders may observe anomalous API calls to Docker or Kubernetes (e.g., 'docker ps', 'kubectl get pods', 'kubectl get nodes'), unusual account activity against the Kubernetes dashboard, or unexpected queries against container metadata endpoints. These events should be correlated with user context and network activity to reveal resource discovery attempts.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.