If a malicious actor is able to create new triggers, they would be able to use valid metric data to trigger malicious actions and re-compromise a newly replaced container or compute instance.
Trigger Malicious Code
CCC.Monitor.TH07
Related Capabilities
| ID | Title | Description |
|---|---|---|
| CCC.Monitor.CP01 | Metric collection | Gathering numerical (quantitative) data points about the performance, health, or behaviour of systems, applications or infrastructure. |
| CCC.Monitor.CP10 | Triggering | Automatically initiating actions like alerts, notifications or automated workflows based on pre-defined conditions being met. |
| CCC.Monitor.CP11 | Integration with Third-Party Tools | Monitoring tools are able to integrate with a number of downstream systems in order to send notifications and alerts, raise tickets and create incident reports. |
External Mappings
| Framework | ID | Relationship | Remarks |
|---|---|---|---|
| MITRE-ATT&CK | T1546 | relates-to | Event Triggered Execution |