You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This rule looks for whether the raw Docker socket was used for container creation as well as a bind mount of /hostfs which could facilitate a container escape and allow command execuiton on the Docker host.
Additional Details
Detail
Value
Type
Templated Match
Category
Unknown/Other
Apply Risk to Entities
device_hostname
Signal Name
Potential Docker Escape via Command Line
Summary Expression
Potential Docker Escape via Command Line on {{device_hostname}}