GPU Management Tool Run in Container


Description

Detects execution of an NVIDIA or AMD GPU management or query tool, such as nvidia-smi or rocm-smi, inside a container. Attackers commonly run these tools immediately after gaining access to a GPU-equipped node to fingerprint the available accelerators before deploying a miner. Inside a workload container this is rarely legitimate outside of machine learning and HPC images. It is a signature-style detection that pairs with the device-access rule to provide both a behavioral and a signature view of the same accelerator-hijacking technique.

Query · falco

spawned_process and container and proc.name in (gpu_management_binaries) and not user_known_gpu_workloads

Rule dependencies

Depends on

  • composes · Falco macro container
    A shared condition, not a detection, so it is not indexed on this site.
  • composes · Falco macro spawned_process
    A shared condition, not a detection, so it is not indexed on this site.
  • composes · Falco macro user_known_gpu_workloads
    A shared condition, not a detection, so it is not indexed on this site.

Analyst notes

GPU management tool run in container | evt_type=%evt.type user=%user.name user_uid=%user.uid user_loginuid=%user.loginuid process=%proc.name proc_exepath=%proc.exepath parent=%proc.pname command=%proc.cmdline terminal=%proc.tty exe_flags=%evt.arg.flags

Raw source GPU Management Tool Run in Container · Falco YAML
Esc
Published by falcosecurity/rules ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
rule: GPU Management Tool Run in Container
desc: 'Detects execution of an NVIDIA or AMD GPU management or query tool, such as
  nvidia-smi or rocm-smi, inside a container. Attackers commonly run these tools immediately
  after gaining access to a GPU-equipped node to fingerprint the available accelerators
  before deploying a miner. Inside a workload container this is rarely legitimate
  outside of machine learning and HPC images. It is a signature-style detection that
  pairs with the device-access rule to provide both a behavioral and a signature view
  of the same accelerator-hijacking technique.

  '
condition: 'spawned_process and container and proc.name in (gpu_management_binaries)
  and not user_known_gpu_workloads

  '
enabled: false
output: GPU management tool run in container | evt_type=%evt.type user=%user.name
  user_uid=%user.uid user_loginuid=%user.loginuid process=%proc.name proc_exepath=%proc.exepath
  parent=%proc.pname command=%proc.cmdline terminal=%proc.tty exe_flags=%evt.arg.flags
priority: CRITICAL
tags:
- maturity_sandbox
- container
- process
- mitre_impact
- T1496

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.