Unusual Process Spawned by Nginx in Ingress-Nginx pod

Cortex XSIAM Analytics Alert Reference by Alert name

Product
Cortex XSIAM
Last date published
2025-12-08
Category
Analytics Alert Reference
Index by
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • XDR Agent

Detection Modules

Detector Tags

Kubernetes - AGENT, Containers

ATT&CK Tactic

ATT&CK Technique

Severity

Low

Description

Unusual Process Spawned by Nginx in Ingress-Nginx pod.

Attacker's Goals

An attacker attempts to use nginx for lateral movement or privilege escalation.

Investigative actions

  • Investigate the child processes for malicious activity and network connections to an external host.

Variations

Unusual process spawned by ingress-nginx with a critical-severity vulnerability found the workload

Synopsis

ATT&CK Tactic

ATT&CK Technique

Severity

High

Description

Unusual Process Spawned by Nginx in Ingress-Nginx pod.

Attacker's Goals

An attacker attempts to use nginx for lateral movement or privilege escalation.

Investigative actions

  • Investigate the child processes for malicious activity and network connections to an external host.