Linux Suspicious Docker Build Command Execution — Detection Rule

The following analytic detects docker build being executed on Dockerfiles within the /tmp directory. This is not a typical location for this activity and can indicate an actor adding a container for malicious future actions.

Read the full analysis on IntelFusions