Container Escape Attempt via Docker Socket, Mount, or Namespace Abuse
Detects suspicious process activity or file access patterns originating from within a container that indicate an attempt to escape to the host. This includes monitoring for the use of tools like nsenter, unshare, and mount, attempts to interact with the docker.sock, or attempts to access critical host paths like /proc/1/root or /host/etc, excluding events originating from authorized container management processes.
Microsoft Sentinel (KQL)

