{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3onetapph500e_firmware-/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.4,"id":"CVE-2022-0185"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elastic Defend","Auditbeat","Elastic Endgame","SentinelOne Cloud Funnel","Linux Kernel","util-linux","Kubernetes"],"_cs_severities":["medium"],"_cs_tags":["privilege-escalation","container-escape","linux"],"_cs_type":"advisory","_cs_vendors":["Elastic","SentinelOne","Linux Foundation"],"content_html":"\u003cp\u003eThe \u003ccode\u003eunshare\u003c/code\u003e command in Linux is a utility used to create new namespaces, providing isolation for processes. While crucial for containerization and security, attackers can misuse \u003ccode\u003eunshare\u003c/code\u003e to escape container boundaries or escalate privileges by manipulating system namespaces. This occurs by creating namespaces that bypass established security controls. This activity is often observed when threat actors attempt to gain unauthorized access to host resources or elevate their privileges within a compromised system. The focus of this detection is on identifying unusual \u003ccode\u003eunshare\u003c/code\u003e executions that deviate from legitimate system management activities.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains initial access to a Linux system, potentially through exploiting a vulnerability in a containerized application.\u003c/li\u003e\n\u003cli\u003eThe attacker executes the \u003ccode\u003eunshare\u003c/code\u003e command.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eunshare\u003c/code\u003e creates new namespaces, isolating the attacker's process from the rest of the system.\u003c/li\u003e\n\u003cli\u003eThe attacker attempts to mount sensitive directories from the host system into the new namespace.\u003c/li\u003e\n\u003cli\u003eUsing the newly gained access, the attacker attempts to modify system files, such as \u003ccode\u003e/etc/passwd\u003c/code\u003e or \u003ccode\u003e/etc/shadow\u003c/code\u003e, to create new privileged accounts.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the elevated privileges to install persistent backdoors or malware on the host system.\u003c/li\u003e\n\u003cli\u003eThe attacker attempts to move laterally to other systems on the network.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves their final objective, such as data exfiltration or system disruption.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation via \u003ccode\u003eunshare\u003c/code\u003e can lead to privilege escalation, container escape, and unauthorized access to sensitive resources on the host system. The impact includes potential data breaches, system compromise, and lateral movement within the network. While the number of victims is unknown, the widespread use of containerization technologies makes this a significant threat, particularly for organizations relying on Linux-based container environments and cloud infrastructures.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eNamespace Manipulation Using Unshare\u003c/code\u003e to your SIEM to detect suspicious \u003ccode\u003eunshare\u003c/code\u003e command executions and tune for your environment.\u003c/li\u003e\n\u003cli\u003eEnable Auditbeat or Elastic Defend to collect the necessary process execution data to trigger the provided Sigma rule, as outlined in the rule's \u003ccode\u003esetup\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eReview and tune the provided Sigma rule's exclusion list based on your environment's legitimate use cases for \u003ccode\u003eunshare\u003c/code\u003e, as described in the \u0026quot;False positive analysis\u0026quot; section.\u003c/li\u003e\n\u003cli\u003eImplement additional monitoring and alerting for unusual \u003ccode\u003eunshare\u003c/code\u003e usage patterns to enhance detection capabilities and prevent future occurrences as recommended in the \u0026quot;Response and remediation\u0026quot; section.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T12:48:38Z","date_published":"2024-01-02T12:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-unshare-namespace-manipulation/","summary":"The `unshare` command is used to create new namespaces in Linux, which can be exploited to break out of containers or elevate privileges by creating namespaces that bypass security controls.","title":"Suspicious Unshare Usage for Namespace Manipulation","url":"https://feed.craftedsignal.io/briefs/2024-01-unshare-namespace-manipulation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}