Spacebar Campaigns

HFA-003 Linux auditd Docker Socket Access Log

Source Alias:
AUD-003
원본 경로:
/var/log/audit/audit.log
auditd key:
hanguel_docker_socket
감시 대상:
/var/run/docker.sock
주요 event.action:
hanguel_docker_socket_access
커버 Technique:
T1611

분석 포인트

KQL

event.action : "hanguel_docker_socket_access"