detecting-container-escape-attempts
mukul975/Anthropic-Cybersecurity-Skills
Detects container escape attempts by monitoring syscall, file, process, network, and audit indicators with runtime tools like Falco, Sysdig, and custom rules to alert on privileged mounts, Docker socket access, sensitive proc paths, cgroup writes, and kernel module loading.