Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1611

T1611Escape to Host

T1611 — Escape to Host is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 16 detection use cases covering it and 5 threat-intel articles citing it.

Privilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
16Use cases
5Articles
0Sub-techniques
1Tactic

Use cases covering this technique (16)

Container escape attempt detected Internal install · alerting DD Falco runtime-security alert Internal actions · alerting DD Kubernetes pod created with privileged flag Internal install · alerting DD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Internal exploit · alerting DSPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD Cisco IOS XE Guestshell Activation and Destroy ESCU actions · hunting P Cisco Isovalent - Potential Escape to Host ESCU actions · hunting P Linux Docker Root Directory Mount ESCU actions · alerting P [LLM] Kubernetes privileged-pod DaemonSet fan-out from compromised LiteLLM workload Bespoke actions · hunting SPDD [LLM] Container PID 1 environment harvest via /proc/1/environ read Bespoke actions · hunting DSΣPDDCS [LLM] Dirty Pipe SUID hijack: root-privileged process executing from /tmp or /dev/shm Bespoke exploit · alerting DSΣPDDCS [LLM] Unprivileged user-namespace creation (unshare CLONE_NEWUSER) preceding Linux privilege escalation Bespoke exploit · hunting DSΣPDDCS [LLM] Host runc binary overwrite from container (CVE-2019-5736 escape-to-host) Bespoke install · alerting DSΣPCS [LLM] runc /proc/self/exe re-exec abuse (CVE-2019-5736 exploit primitive) Bespoke exploit · hunting DSΣPDDCS

Articles citing this technique (5)