""ET INFO External Host Sending Docker Swarm Join Command""

SID: 2031587

Revision: 3

Class Type: misc-activity

Metadata: attack_target Server, created_at 2021_01_28, deployment Perimeter, performance_impact Low, signature_severity Informational, tag Docker, updated_at 2023_06_23

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: [2375,2376]

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: "/swarm/join"

  • Value: "|7b 22|ListenAddr|22 3a 22|" Depth: 15

  • Value: "|22|RemoteAddrs|22 3a 5b 22|"

  • Value: "|2c 22|JoinToken|22 3a 22|"

  • Value: !"Referer|3a 20|"

Within:

PCRE: "/\/swarm\/join$/U"

Special Options:

  • http_method

  • http_uri

  • http_client_body

  • http_client_body

  • http_client_body

  • http_header

source