Skip to content
Threat Feed
low advisory

Detection of Mount Command Execution in Privileged Containers

This brief describes a detection mechanism for identifying potential container escapes and host-level privilege escalation via the unauthorized use of the mount utility within privileged containers.

Privileged containers are deployed with extensive capabilities equivalent to the host machine, creating a high-risk environment if an attacker gains code execution. The mount utility, when executed within such a context, allows an adversary to attach host file systems to the container's namespace. This capability is frequently abused for container escapes and host-level privilege escalation. Monitoring the execution of mount within containers marked with container.security_context.privileged == true provides a critical defensive signal against unauthorized host file access. Defenders should establish a baseline for legitimate administrative, backup, and monitoring processes that require mounting operations to minimize noise and improve signal fidelity in containerized production environments.

Impact

Successful exploitation of this technique permits an attacker to bridge the isolation between the container and the host OS. This can lead to the exfiltration of sensitive configuration files, credentials, or system binaries, ultimately resulting in full host compromise and the potential for lateral movement within the infrastructure.

Recommendation

  • Deploy the provided EQL detection logic to identify mount execution within privileged containers.
  • Audit all containers currently running with the privileged security context and enforce the principle of least privilege by stripping unnecessary capabilities.
  • Isolate containers that trigger this alert to prevent potential unauthorized access to host file systems during investigation.
  • Implement exception lists in your SIEM/detection platform for known, legitimate maintenance or monitoring tasks that perform valid mounting operations.

Immediate actions

Deploy process-creation detection for mount execution in privileged containers

Detection Engineering 48h

Threat Hunt

Identify all running containers with privileged security context

T1611 high high confidence hunt now

Data: Container runtime configuration logs