Mythic C2 Implant Build via Docker - Suspicious Container Invocation
This rule detects potential Mythic C2 implant or payload build activity occurring via Docker. It monitors for executions of docker.exe, docker-compose.exe, or docker commands initiated by shells (cmd.exe, powershell.exe) containing keywords associated with the Mythic C2 framework, while explicitly excluding common CI/CD runner parent processes to reduce noise.
Microsoft Sentinel (KQL)

