Container Escape via Host File System Access or Namespace Manipulation
This rule detects potential container escape attempts on Linux systems by monitoring suspicious file system access patterns to the host's root directory or process creation events involving 'mount', 'nsenter', or 'chroot' commands with parameters indicative of host interaction. Specifically, it looks for file operations on '/proc/1/root', '/proc/1/cwd', '/proc/1/exe', '/proc/1/fd', '/proc/1/ns', '/proc/1/environ', '/proc/1/mounts' or paths starting with '/host', '/hostroot', '/host-root', '/node-root'. It also flags 'mount' commands targeting '/proc/1/root', '/proc/1', 'nsenter', '--target 1', 'hostpath', or '/host', 'nsenter' commands with namespace manipulation arguments, and 'chroot' commands targeting '/proc/1/root', '/host', or '/hostroot'. These activities are commonly associated with adversaries trying to break out of a containerized environment to gain access to the underlying host.
SentinelOne

