A contained process attempted to escape using the 'notify on release' feature
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Escape to Host (T1611)
Severity
Medium
Description
A contained process attempted to escape the host by leveraging the Docker's 'notify on release' feature. The calling process modified relevant files that might trigger a command on the host.
Attacker's Goals
Execute arbitrary commands on the host and gain a larger foothold.
Investigative actions
Check which commands were executed on the host afterward.
Look for the root cause of the execution within the container.
Examine the release_agent script content on the container.
Variations
PreviousA contained executable was executed by an unusual process
NextA container registry was created or deleted
Was this helpful?
