Escape to Host T1611

Tactic: Privilege Escalation

Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.

Events covered

4 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 62 rules share fields, values, and exclusions.

Fields filtered most (74 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType36eq 18, in 18exec, ProcessRollup2, exec_event, io.k8s.core.v1.pods.create, executed
event.type26eq 26start, change, creation
host.os.type25eq 25
process_name25eq 21, in 8, starts_with 3docker, bash, busybox, mount, chroot
process.args19eq 13, in 11, starts_with 5, wildcard 3, contains 2--privileged, --mount, -t, nsenter, --net-host
data_stream.dataset15eq 15gcp.audit, kubernetes.audit_logs
kubernetes.audit.objectRef.resource8eq 8pods, nodes
container.id7wildcard 4, starts_with 3*, ?
kubernetes.audit.annotations.authorization_k8s_io/decision7eq 7allow
kubernetes.audit.verb7in 5, eq 2create, patch, update
event.outcome6eq 6success
username6contains 6serviceaccount
event.category5eq 5process, network
parent_process_name5in 4, eq 1java, zz-proxmox-boot, bash, containerd-shim-runc-v2, csh
process.entry_leader.entry_meta.type5eq 5container

Top indicator values (351 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
221078
EventTypeeq
exec
12576
EventTypein
exec
12201
EventTypein
executed
998
EventTypein
start
7163
EventTypein
ProcessRollup2
6117
EventTypein
exec_event
6149
EventTypein
io.k8s.core.v1.pods.create
45
EventTypein
io.k8s.core.v1.pods.patch
45
EventTypein
io.k8s.core.v1.pods.update
45
EventTypein
process_started
483
data_stream.dataseteq
gcp.audit
869
data_stream.dataseteq
kubernetes.audit_logs
736
process.argseq
run
810
kubernetes.audit.annotations.authorization_k8s_io/decisioneq
allow
725
kubernetes.audit.objectRef.resourceeq
pods
711
event.outcomeeq
success
6369
usernamecontains
serviceaccount
624
kubernetes.audit.verbin
patch
520
kubernetes.audit.verbin
update
519
kubernetes.audit.verbin
create
417
process.entry_leader.entry_meta.typeeq
container
513
container.idwildcard
*
426
event.categoryeq
process
4142
process_nameeq
docker
45
process_nameeq
mount
49
process_namein
bash
4202
process_namein
busybox
468
process_namein
dash
4170
process_namein
fish
4163

Exclusions (270 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
gcp.audit.request.metadata.ownerReferences.kindin
daemonset
6
gcp.audit.request.metadata.ownerReferences.kindin
replicaset
6
gcp.audit.request.metadata.ownerReferences.kindin
statefulset
6
resourcene
pods
6
responseStatus.codege
1
6
responseStatus.codege
400
6
responseStatus.codele
16
6
usernamein
aksService
6
usernamein
masterclient
6
usernamestarts_with
system:
6
verbne
create
6
kubernetes.audit.requestObject.spec.containers.imagestarts_with
rancher/system-agent
5
namespacein
gke-system
5
namespacein
kube-node-lease
5
namespacein
kube-public
5

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 2 rules

Elastic 45 rules

Splunk 3 rules

Kusto 2 rules

Panther 10 rules