CrowdStrike Research Challenges Containerized Application Predictability Assumptions
ID: 5edf0c3f-81d7-5378-a753-755442e17ae0
STIX ID: report--5edf0c3f-81d7-5378-a753-755442e17ae0
Feed Name: Crowdstrike Blog
Date Published: 2024-10-29
Date Updated: 2026-04-27
Author: Sergey Kozlov - Ryan Inghilterra - Ajit Dhumale
CrowdStrike analyzed billions of container events across popular applications (e.g., Elasticsearch, Kafka, MongoDB, MySQL, Nginx, PostgreSQL, RabbitMQ, Redis, ZooKeeper) and found that many Linux utilities frequently linked to living-off-the-land post-exploitation activity (e.g., apt, curl, ssh, tar, wget) are routinely and legitimately executed inside containers. These findings challenge the assumption that containerized workloads are immutable and predictable, indicating that detection strategies based solely on behavioral deviations are insufficient and require more context-aware approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
