For the complete documentation index, see llms.txt. This page is also available as Markdown.

Kubernetes nsenter container escape

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

7 Days

Required Data

XDR Agent

Detector Tags

Kubernetes - AGENT, Containers

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Escape to Host (T1611)

Severity

Informational

Description

The nsenter command was used to execute a process in the context of the initialization process.

Attacker's Goals

Attackers may break out of a container to run commands on the host.

Investigative actions

Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.

Variations

Kubernetes nsenter container escape from a new Pod

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Escape to Host (T1611)

Severity

Medium

Description

The nsenter command was used to execute a process in the context of the initialization process.

Attacker's Goals

Attackers may break out of a container to run commands on the host.

Investigative actions

Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.

Kubernetes nsenter container escape from a Pod

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Escape to Host (T1611)

Severity

Low

Description

The nsenter command was used to execute a process in the context of the initialization process.

Attacker's Goals

Attackers may break out of a container to run commands on the host.

Investigative actions

Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.

Was this helpful?