Container Escape: nsenter/unshare/chroot or docker.sock Access in Container
Detects various techniques used by an attacker to escape a container environment or gain unauthorized access to host-level resources. This includes the execution of namespace manipulation tools (nsenter, unshare, chroot), unauthorized access to the docker.sock Unix socket, mounting of host filesystems from within a container, and direct attempts to access the host's /proc/1 namespace files.
SentinelOne

