detect-container-escape-k8s
Installation
SKILL.md
detect-container-escape-k8s
Use when
- Kubernetes audit telemetry is already normalized by
ingest-k8s-audit-ocsf - you want deterministic findings for post-deploy escape-to-host changes
- you need native or OCSF findings for patch-driven container-escape signals
Attack patterns detected
This PR ships the K8s-audit-first subset of issue #274: three single-event
rules that do not depend on Falco, Tracee, or operator/deployer history.
Rule 1: Risky spec patch (T1611)
Fires when a patch request introduces one or more of: