logo

CrowdStrike Research Challenges Containerized Application Predictability Assumptions

ID: 5edf0c3f-81d7-5378-a753-755442e17ae0

STIX ID: report--5edf0c3f-81d7-5378-a753-755442e17ae0

Feed Name: Crowdstrike Blog

Date Published: 2024-10-29

Date Updated: 2026-04-27

Author: Sergey Kozlov - Ryan Inghilterra - Ajit Dhumale

...
...

CrowdStrike analyzed billions of container events across popular applications (e.g., Elasticsearch, Kafka, MongoDB, MySQL, Nginx, PostgreSQL, RabbitMQ, Redis, ZooKeeper) and found that many Linux utilities frequently linked to living-off-the-land post-exploitation activity (e.g., apt, curl, ssh, tar, wget) are routinely and legitimately executed inside containers. These findings challenge the assumption that containerized workloads are immutable and predictable, indicating that detection strategies based solely on behavioral deviations are insufficient and require more context-aware approaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.