Skip to main content
Welcome, Dropzone!
You have 1 day left in your trial.
Upgrade
  • Recent
    • Monitors
      Monitors
    • Logs
      Logs
    • Monitor Status: User Exec into a Pod - standardized
      Monitor Status: User Exec into a Pod - standardized
    • Integrations
      Integrations
    • Signals Explorer
      Signals Explorer
    • Watchdog
      Watchdog
    • Cloud SIEM
      Cloud SIEM
    • Dropzone Dec 02 2024 14:15
      Dropzone Dec 02 2024 14:15
    • Plan
      Plan
    • Manage Log Retention
      Manage Log Retention
  • Dashboards
    Dashboards
    Docs
    • Dashboard List
    • New Dashboard
    • Reports
    Notebooks
    Docs
    • Notebooks List
    • New Notebook
    Quick Graph
    Docs
  • Monitors
    Monitors
    Docs
    • Monitors List
    • Settings
    • New Monitor
    • Triggered Monitors
    • Downtimes
    Check Summary
    Docs
  • Watchdog
  • Service Mgmt
    Services
    Docs
    • Service Catalog
    • Add a Service
    • Scorecards
    • SLOs
    Incidents
    Docs
    • Incident List
    • Settings
    • Declare Incident
    Event Management
    • Event Correlations
    • Settings
    • Explorer
    Appsnew
    • App Builder
    • New App
    • Workflow Automation
    • New Workflow
    Case Managementnew
    Docs
    Teamsnew
  • Infrastructure
    Resource Catalog
    Docs
    Universal Service Monitoringnew
    Docs
    Hosts
    Docs
    • Host Map
    Containers
    Docs
    • Container Map
    • Container Images
    • Kubernetes Overview
    • Kubernetes Explorer
    • ECS Explorernew
    Processes
    Docs
    Serverless
    Docs
    Cloud Network
    Docs
    • Analytics
    • Network Map
    • DNS Queries
    Network Devices
    Docs
    • Device Topology Mapnew
    • NetFlow
    Cloud Cost
    Docs
  • APM
    Services
    Docs
    • Service Catalog
    • Scorecards
    • Add a Service
    • Settings
    • Service Map
    Traces
    Docs
    • Explorer
    • Generate Metrics
    • Ingestion Control
    • Retention Filters
    • Sensitive Data Scanner
    Profiles
    Docs
    • Explorer
    • Comparison
    Dynamic Instrumentationnew
    Docs
    Database Monitoring
    Docs
    Data Streams Monitoring
    Docs
    Data Jobs Monitoringnew
    API Catalog
    Docs
  • Digital Experience
    Synthetic Monitoring & Testing
    Docs
    • Tests
    • Settings
    • New Test
    • Explorer
    • Continuous Testing
    • Test Coverage
    Real User Monitoring
    Docs
  • Software Delivery
    Intro to CI Visibility
    Docs
    Intro to Test Optimization
    Docs
    Intro to Code Analysispreview
    Docs
    Quality Gatespreview
    Docs
    DORA Metricspreview
    Docs
  • Security
    Security
    • Overviewnew
    • Settings
    • Signals Explorer
    • Research Feed
    Application Security
    Docs
    Cloud Security Management
    Docs
    Cloud SIEM
    Docs
    • Content Packs
    • Signals Explorer
    • Settings
    • Detection Rules
    • Historical Jobs
    Sensitive Data Scanner
    Docs
    • Summary
    • Configuration
  • LLM Observability
    LLM Observability
    • Applications
    • Traces
    • Integrations
    • Settings
    • Clusters
  • Errors
  • Metrics
    Metrics
    Docs
    • Explorer
    • Summary
    • Volume
  • Logs
    Search & Analytics
    Docs
    • Explorer
    • Patterns
    • Transactions
    • Manage Log Retention
    • Manage Flex Logs Compute
    • Rehydrate from Archives
    • Data Access Settings
    Log Stream
    Docs
    • Pipelines
    • Log Forwarding
    • Generate Metrics
    • Add a Log Source
    • Standard Attributes
    • Sensitive Data Scanner
    Observability Pipelinesnew
    Docs
  • Integrations
    • Integrations
    • Marketplace
    • Agent
    • Fleet Automationnew
    • Reference Tablespreview
    • Source Code Integration
    • IDE Plugins
    • Start a call on CoScreen
    • About CoScreen
    • DocumentationExternal Link
  • lab+datadog@dropzone.ai
    lab+datadog@dropzone.ai
    Dropzone AI
    Dropzone AI
    • Personal Settings
      lab+datadog@dropzone.ai
      lab+datadog@dropzone.ai
      Log In to Mobile
      My Profile
      My Preferences
      My Organizations
      My Application Keys
      Theme: light
      ctrl+opt+d
      Organization Settings
      Dropzone AI
      Dropzone AI
      Plan & Usage
      Users
      Teams
      Roles
      Service Accounts
      API Keys
      Application Keys
      Audit Trail
      Sensitive Data Scanner
      Switch organizations
      • Dropzone AI
        Dropzone AI
        Dropzone AI
        Signed in
        Dropzone AI
        Dropzone AI
        Dropzone AI
        Signed in
Invite
Help
Security PlatformSecurity
Signals
Cloud SIEM
Application Security
Cloud Security
Research Feed

Signals Explorer

3h
Security Platform
tactic:ta0002-execution⁠
Set as Notification
01
16:0016:1516:3016:4517:0017:1517:3017:4518:0018:1518:3018:45
2m17:18:00
Angle Right
My Teams
UsersYour organization has no Teams
Create Teams
triage
Archive Reason
Archive Reason
Assignee
Assignee
Signal State
Signal State
core
Source
Source
Severity
Severity
Scope
Scope
Security
Security
Host
Host
Host
Client IP
Client IP
Destination IP
Destination IP
Instance ID
Instance ID
AWS
Account ID
Account ID
ARN
ARN
Bucket Name
Bucket Name
Cache Cluster ID
Cache Cluster ID
Certificate ARN
Certificate ARN
Cluster ID
Cluster ID
Database Instance ID
Database Instance ID
Database Name
Database Name
Database Snapshot ID
Database Snapshot ID
Domain Name
Domain Name
Elastic Search ARN
Elastic Search ARN
Flow Log
Flow Log
Function Name
Function Name
Group ID
Group ID
Group Name
Group Name
Instance ARN
Instance ARN
Load Balancer ARN
Load Balancer ARN
Load Balancer Name
Load Balancer Name
Network ACL ID
Network ACL ID
Policy ARN
Policy ARN
Policy ID
Policy ID
Policy Name
Policy Name
Queue ARN
Queue ARN
Role Name
Role Name
Rule Number
Rule Number
Snapshot ID
Snapshot ID
Table Name
Table Name
Topic ARN
Topic ARN
Trail ARN
Trail ARN
User
User
Volume ID
Volume ID
VPC Endpoint ID
VPC Endpoint ID
VPC ID
VPC ID
Web Access
IP
IP
Status Code
Status Code
URL Path
URL Path
User Agent
User Agent
Compliance
Control
Control
Framework
Framework
Requirement
Requirement
GCP
Workload Security
Workflow
User
Security Activity
Kubernetes
MITRE ATT&CK
Core
Containers
Others
Too many facets? Aliasing can merge duplicate facets. Unused facets can also be hidden (saved as part of a Saved View).
1 signal found
All
1
1
Open
1
1
Archived
0
0
Under Review
0
0
Severity
Severity
Creation Date
Creation Date
Creation Date
Title
Title
info
Dec 2, 5:19:44 pm
Last seen: 2 days ago

User Exec into a Pod - standardized
User Exec into a Pod - standardized

kubernetes
attack
TA0002-Execution
T1059-Command-And-Scripting-Interpreter
attack
TA0002-Execution
T1059-Command-And-Scripting-Interpreter
usr.name:arn:aws:sts::211125570273:assumed-role/dropzone/dropzone
  • Copyright Datadog, Inc. 2024
  • Version:35.50398617
  • Master Subscription Agreement
  • Privacy Policy
  • Cookie Policy
  • Datadog Status →: All Systems Operational All Systems Operational