detect-container-escape-k8s

Installation
SKILL.md

detect-container-escape-k8s

Use when

  • Kubernetes audit telemetry is already normalized by ingest-k8s-audit-ocsf
  • you want deterministic findings for post-deploy escape-to-host changes
  • you need native or OCSF findings for patch-driven container-escape signals

Attack patterns detected

This PR ships the K8s-audit-first subset of issue #274: three single-event rules that do not depend on Falco, Tracee, or operator/deployer history.

Rule 1: Risky spec patch (T1611)

Fires when a patch request introduces one or more of:

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
detect-container-escape-k8s — msaad00/cloud-ai-security-skills