MITRE ATLAS Mapped 2026 Top AI Agent Security Detection – Escape to Host (AML.T0105)
Detects attempts by AI agent code-interpreter or sandbox processes to break out of their containerized environment. The rule monitors for the execution of common container escape techniques, such as namespace manipulation (nsenter, unshare), mounting host filesystems, accessing sensitive host devices like /dev/kmsg or /dev/mem, or referencing host-level paths from within an isolated AI agent execution process.
YARA-L

