Linux Suspicious Docker Build Command Execution — Detection Rule
The following analytic detects docker build being executed on Dockerfiles within the /tmp directory. This is not a typical location for this activity and can indicate an actor adding a container for malicious future actions.