container-technique

Installation
SKILL.md

container-technique

Goal: Exploit container environments (Docker, Kubernetes, LXC) to achieve host-level code execution, horizontal pod movement, or cluster takeover.

When this technique applies

  • You have gained a shell via Web RCE or SSH and notice .dockerenv, kubepods in cgroups, or specific mount patterns.
  • You have acquired compromised Kubeconfigs or Service Account tokens.

The Escape Workflow

1. Internal Reconnaissance

Determine the isolation boundaries.

  • Am I in a container?: ls -la /.dockerenv ; cat /proc/1/cgroup
  • What privileges do I have?: capsh --print (look for CAP_SYS_ADMIN, CAP_SYS_MODULE, CAP_SYS_PTRACE).
  • Network mapping: Look for kube-dns or metadata endpoints (e.g. 169.254.169.254 or GCP/Azure equivalents).

2. Hunting for Escape Vectors

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
container-technique — aeondave/malskill