Escape to Host T1611
Tactic: Privilege Escalation
Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.
Events covered
4 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Defender-DeviceProcessEvents | any | Process activity |
| Defender-DeviceProcessEvents | ProcessCreated | Process created |
| ESF | exec | Process Execution |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 62 rules share fields, values, and exclusions.
Fields filtered most (74 distinct)
These fields appear most often in rule filters.
Top indicator values (351 distinct)
These values appear most often in rule predicates.
Exclusions (270 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 2 rules
Elastic 45 rules
- Chroot Execution Detected via Defend for Containers
- Chroot Execution in Container Context on Linux
- Container Runtime CLI Execution with Suspicious Arguments
- DebugFS Execution Detected via Defend for Containers
- Docker Release File Creation
- Egress Connection from Entrypoint in Container
- File System Debugger Launched Inside a Container
- GKE API Server Proxying Request to Kubelet
- GKE Container Created with Excessive Linux Capabilities
- GKE Ephemeral Container Added to Pod
- GKE Pod Created with a Sensitive hostPath Volume
- GKE Pod Created With HostIPC
- GKE Pod Created With HostNetwork
- GKE Pod Created With HostPID
- GKE Privileged Pod Created
- Kernel Load or Unload via Kexec Detected
- Kubernetes API Server Proxying Request to Kubelet
- Kubernetes Container Created with Excessive Linux Capabilities
- Kubernetes Ephemeral Container Added to Pod
- Kubernetes Pod Created with a Sensitive hostPath Volume
- Kubernetes Pod Created With HostIPC
- Kubernetes Pod Created With HostNetwork
- Kubernetes Pod Created With HostPID
- Kubernetes Privileged Pod Created
- Mount Execution Detected via Defend for Containers
- Mount Launched Inside a Container
- Namespace Manipulation Using Unshare
- Namespace Manipulation Using Unshare in a Container
- Nsenter Execution with Target Flag Inside Container
- Nsenter to PID Namespace via Auditd
- Pod or Container Creation with Suspicious Command-Line
- Potential Cgroup Privilege Escalation/Container Escape via Mount
- Potential Chroot Container Escape via Mount
- Potential Container Escape via Kernel core_pattern Modification
- Potential Docker Escape via Nsenter
- Potential notify_on_release Container Escape Detected via Defend for Containers
- Potential Privilege Escalation in Container via Runc Init
- Potential Privilege Escalation through Writable Docker Socket
- Potential Privilege Escalation via Container Misconfiguration
- Potential release_agent Container Escape Detected via Defend for Containers
- Privileged Container Creation with Host Directory Mount
- Privileged Docker Container Creation
- Suspicious Container Runtime CLI Execution
- Suspicious Privileged Docker Execution
- Unusual Process Connection to Docker or Containerd Socket
Splunk 3 rules
- Cisco IOS XE Guestshell Activation and Destroy
- Cisco Isovalent - Potential Escape to Host
- Linux Docker Root Directory Mount
Kusto 2 rules
Panther 10 rules
- GCP K8s Pod Attached To Node Host Network
- GCP K8S Pod Create Or Modify Host Path Volume Mount
- GCP K8s Pod Using Host PID Namespace
- Kubernetes Pod Attached To Host Network
- Kubernetes Pod Created in System Namespace
- Kubernetes Pod Using Host IPC Namespace
- Kubernetes Pod Using Host PID Namespace
- Kubernetes Pod with Dangerous Linux Capabilities
- Kubernetes Pod With HostPath Volume Mount
- Upwind Runtime Detection Passthrough