Adversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry. A remote build request may be sent to the Docker API that includes a Dockerfile that pulls a vanilla base image, such as alpine, from a public or local registry and then builds a custom image upon it.(Citation: Docker Build Image) An adversary may take advantage of that build API to build a custom image on the host that includes malware downloaded from their C2 server, and then they may utilize [Deploy Container](https://attack.mitre.org/techniques/T1610) using that custom image.(Citation: Aqua Build Images on Hosts)(Citation: Aqua Security Cloud Native Threat Report June 2021) If the base image is pulled from a public registry, defenses will likely not detect the image as malicious since it’s a vanilla image. If the base image already resides in a local registry, the pull may be considered even less suspicious since the image is already in the environment.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Limit Access to Resource Over Network
is blocked by Detection Strategy for Build Image on Host
is blocked by Privileged Account Management
is blocked by Network Segmentation
is blocked by Audit
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Boundary Protection
is blocked by Remote Access
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Vulnerability Scanning
Impressum Deutsch Englisch