Container Escape via Runtime Socket Access or Privileged Namespace Break-out (T1

Detects host-side indicators of potential container escapes and unauthorized access, including mounting sensitive container runtime sockets, executing containers with privileged flags, host namespace sharing, and the use of nsenter to break out of a container context.