Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1611

T1611Escape to Host

T1611 — Escape to Host is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 22 detection use cases covering it and 10 threat-intel articles citing it.

Privilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
22Use cases
10Articles
0Sub-techniques
1Tactic

Use cases covering this technique (22)

Container escape attempt detected Internal install · alerting DD Falco runtime-security alert Internal actions · alerting DD Kubernetes pod created with privileged flag Internal install · alerting DD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Internal exploit · alerting DSPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD Cisco IOS XE Guestshell Activation and Destroy ESCU actions · hunting P Cisco Isovalent - Potential Escape to Host ESCU actions · hunting P Linux Docker Root Directory Mount ESCU actions · alerting P [LLM] Exposure hunt: ESX/ESXi VM-escape + info-disclosure host flaws (CVE-2026-47876 / CVE-2026-41703 / CVE-2026-41709) Bespoke exploit · hunting DSP [LLM] Unprivileged Linux tc clsact/flower/gact traffic-control manipulation (CVE-2026-53264 trigger) Bespoke exploit · hunting DSΣPDDCS [LLM] Fission Environment CRD create/update with dangerous SecurityContext on standalone container (CVE-2026-50566) Bespoke exploit · alerting SΣPDD [LLM] Privileged / dangerous-capability pod scheduled in Fission function/builder namespace by executor SA Bespoke install · alerting SPDD [LLM] Kubernetes privileged-pod DaemonSet fan-out from compromised LiteLLM workload Bespoke actions · hunting SPDD [LLM] Malicious privileged DaemonSet apply in kube-system (host-provisioner-iran / host-provisioner-std / kamikaze) Bespoke install · alerting DSΣPDDCS [LLM] Host-root mount wiper: chroot /mnt/host reboot -f or rm -rf / --no-preserve-root Bespoke actions · alerting DSΣPDDCS [LLM] Container PID 1 environment harvest via /proc/1/environ read Bespoke actions · hunting DSΣPDDCS [LLM] Dirty Pipe SUID hijack: root-privileged process executing from /tmp or /dev/shm Bespoke exploit · alerting DSΣPDDCS [LLM] Unprivileged user-namespace creation (unshare CLONE_NEWUSER) preceding Linux privilege escalation Bespoke exploit · hunting DSΣPDDCS [LLM] Host runc binary overwrite from container (CVE-2019-5736 escape-to-host) Bespoke install · alerting DSΣPCS [LLM] runc /proc/self/exe re-exec abuse (CVE-2019-5736 exploit primitive) Bespoke exploit · hunting DSΣPDDCS

Articles citing this technique (10)