<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Containers on RGROSEC</title><link>https://aegrah.github.io/tags/containers.html</link><description>Recent content in Containers on RGROSEC</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright © Ruben Groenewoud</copyright><lastBuildDate>Fri, 20 Mar 2026 12:00:00 +0200</lastBuildDate><atom:link href="https://aegrah.github.io/tags/containers/index.xml" rel="self" type="application/rss+xml"/><item><title>Linux &amp; Cloud Detection Engineering - TeamPCP Container Attack Scenario</title><link>https://aegrah.github.io/post/2026-03-20-teampcp-container-attack-scenario.html</link><pubDate>Fri, 20 Mar 2026 12:00:00 +0200</pubDate><guid>https://aegrah.github.io/post/2026-03-20-teampcp-container-attack-scenario.html</guid><description>
At Elastic Security Labs, I published a real-world walkthrough of TeamPCP's multi-stage container compromise, demonstrating how Elastic's Defend for Containers (D4C) surfaces runtime signals across each stage of the attack chain. Rather than analyzing isolated techniques in abstraction, we follow the attack as it unfolds inside a containerized environment based on the TeamPCP cloud-native ransomware operation documented by Flare.
The scenario spans nearly the entire MITRE ATT&amp;amp;CK lifecycle—from initial execution via curl | bash and Kubernetes environment discovery, through lateral movement via kube.</description></item><item><title>Linux &amp; Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)</title><link>https://aegrah.github.io/post/2026-03-19-getting-started-with-defend-for-containers.html</link><pubDate>Thu, 19 Mar 2026 12:00:00 +0200</pubDate><guid>https://aegrah.github.io/post/2026-03-19-getting-started-with-defend-for-containers.html</guid><description>
At Elastic Security Labs, I published a comprehensive walkthrough of Elastic's Defend for Containers (D4C) integration, covering Kubernetes-based deployment, BPF-enriched runtime telemetry analysis, and the practical application of policy-driven security controls for containerized Linux environments.
Defend for Containers arrived in Elastic Stack 9.3.0 as a runtime security integration that captures process execution and file access events enriched with container and orchestration context. This post provides a practical starting point for detection engineers: how to deploy D4C via Elastic Agent in Kubernetes, how its selector-response policy model works, which fields matter for detection logic (capabilities, interactive execution, container privilege context), and how to enable the pre-built detection ruleset.</description></item></channel></rss>