logo

Preventing Container Escape Attempts with Falcon Cloud Security's Enhanced Runtime Capabilities

ID: 3eb85fd4-b89e-5762-bf39-3281151e6591

STIX ID: report--3eb85fd4-b89e-5762-bf39-3281151e6591

Feed Name: Crowdstrike Blog

Date Published: 2025-07-22

Date Updated: 2026-04-27

Author: Bogdan Trufanda - Dumitra Dragos - Suraj Sahu

...
...

This report outlines common container escape vectors and initial access techniques in containerized environments, emphasizing risks from privileged containers, unsafe volume mounts (e.g., /var/run/docker.sock, /, /proc, /sys), kernel vulnerabilities like Dirty Pipe (CVE-2022-0847), and excessive Linux capabilities. It also highlights frequent abuse of exposed Docker/Kubernetes APIs and misconfigured RBAC, framing a kill chain where an exposed Docker API can escalate to full cloud environment compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.