Suspicious Container Environment Reconnaissance in Serverless Build

PremiumReviewedSigma · Medium · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-11
Updated
2026-09-11

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects container-awareness reconnaissance that reads /proc/self/cgroup, the /.dockerenv marker file or /etc/passwd from inside a serverless build environment. In this Cloud Functions abuse chain a malicious package.json runs during the build and fingerprints the container before pivoting with the attached Cloud Build service account, so this recon precedes privilege escalation and Ngrok-based exfiltration.

Related detections5 linkedT1613 — drag to rearrange
Suspicious Kubernetes Secret Enumeration via kubectl
Suspicious Kubernetes API Request From Anonymous User
Suspicious Kubernetes Secret and Permission Enumeration via kubectl (via process_creation)
Suspicious Anonymous Access to Kubernetes API Server via Audit Log
Kubernetes audit log signals potential tool and shell enumeration/execution activity
Suspicious Container Environment Reconnaissance in Serverless Build
Pivot detection · T1613 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.