Container Privileged Escape Indicators via Docker/ContainerD on Windows

Detects potential container breakout attempts on Windows systems by monitoring for the launch of privileged containers with sensitive host paths mounted, the execution of host-level processes directly spawned by container runtime binaries (docker.exe, containerd.exe), and direct access to sensitive host filesystems (e.g., C:\windows, C:\etc, C:\programdata) by container runtimes.