Unauthenticated Docker API abuse: privileged container create with host mounts

Detects malicious interactions with an unauthenticated Docker daemon API, specifically identifying the creation of privileged containers with host bind mounts, the deployment of containers with specific naming conventions for network reconnaissance (netns-probe/net-setup), subsequent container start events, and the use of the Docker exec API to perform host namespace escapes via nsenter.