{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/docker-engine/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Docker Engine"],"_cs_severities":["medium"],"_cs_tags":["linux","container-security","persistence"],"_cs_type":"advisory","_cs_vendors":["Docker"],"content_html":"\u003cp\u003eSecurity researchers have identified a pattern of suspicious activity involving the use of the 'docker build' command on Linux systems. Attackers often stage malicious Dockerfiles within temporary directories such as /tmp to minimize their footprint or obfuscate their activity. Because the /tmp directory is typically used for transient files and is rarely a legitimate location for software builds, this behavior is a high-fidelity indicator of potential unauthorized container deployment or post-exploitation activities. This detection is particularly relevant for Linux environments using the Docker Engine, where attackers may seek to gain additional persistence or facilitate further command execution by leveraging the container runtime. Defenders should monitor for command-line arguments that reference the /tmp path during docker build operations to identify potential malicious intent early in the kill chain.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to the Linux host via an exploit or stolen credentials.\u003c/li\u003e\n\u003cli\u003eAttacker downloads or creates a malicious Dockerfile.\u003c/li\u003e\n\u003cli\u003eAttacker places the Dockerfile into a writable temporary directory like /tmp.\u003c/li\u003e\n\u003cli\u003eAttacker executes 'docker build' pointing to the temporary directory using the -f flag or by executing from within that path.\u003c/li\u003e\n\u003cli\u003eThe Docker daemon processes the malicious configuration, often pulling malicious base images or executing internal commands during the build phase.\u003c/li\u003e\n\u003cli\u003eThe container image is successfully built and registered in the local Docker engine.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the new container to execute malicious code, achieving persistence or gaining a sandbox environment for further operations.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to establish persistent containerized backdoors, bypass host-level security controls, or gain a stable execution environment for secondary tools. This activity is frequently observed in Linux Post-Exploitation scenarios where the attacker attempts to expand their influence within the compromised infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect suspicious 'docker build' executions originating from temporary directories.\u003c/li\u003e\n\u003cli\u003eEstablish a process for reviewing developer-approved usage of build environments to reduce noise from legitimate development activities.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon for Linux (or equivalent EDR telemetry) to capture full command-line arguments and parent process information, which is critical for identifying the origin of the build command.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T15:16:51Z","date_published":"2026-08-07T15:16:51Z","id":"https://feed.craftedsignal.io/briefs/2026-08-suspicious-docker-build/","summary":"Detection of docker build commands executed on Dockerfiles located in temporary directories, a common indicator of unauthorized container deployment or persistence attempts on Linux hosts.","title":"Suspicious Docker Build Execution in Temporary Directories","url":"https://feed.craftedsignal.io/briefs/2026-08-suspicious-docker-build/"}],"language":"en","title":"CraftedSignal Threat Feed - Docker Engine","version":"https://jsonfeed.org/version/1.1"}