Docker Socket Container Escape Probing Post-Compromise
This rule detects processes attempting to interact with the Docker daemon via its Unix domain socket (/var/run/docker.sock). This is a common technique used by attackers to escape from a container, gain host-level control, or execute arbitrary container administration commands.
Cortex XDR

