Most Important Detection 2026: Kubernetes Container Escape and Privilege Escalation
This rule detects potential container escape and privilege escalation attempts within a Kubernetes environment by monitoring for the creation of privileged pods, dangerous host mounts (such as /var/run/docker.sock or hostPath root mounts), and the use of escape-oriented utilities like nsenter or chroot, or access to the host's filesystem via /proc/1/root.
Splunk (SPL)

