1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1613 Container and Resource Discovery — Detection Rules

Detection workspace for T1613 Container and Resource Discovery: 1 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1613 Container and Resource Discovery

COUNT(orchestrator_list_or_get_requests BY identity, 5m) >= threshold AND identity NOT_IN approved_cluster_admins -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0490 Detection Strategy for Container and Resource Discovery

AN1352 Analytic 1352

Detection of adversary attempts to enumerate containers, pods, nodes, and related resources within containerized environments. Defenders may observe anomalous API calls to Docker or Kubernetes (e.g., 'docker ps', 'kubectl get pods', 'kubectl get nodes'), unusual account activity against the Kubernetes dashboard, or unexpected queries against container metadata endpoints. These events should be correlated with user context and network activity to reveal resource discovery attempts.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1613 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.