Detection of Mount Command Execution in Privileged Containers
This brief describes a detection mechanism for identifying potential container escapes and host-level privilege escalation via the unauthorized use of the mount utility within privileged containers.
Privileged containers are deployed with extensive capabilities equivalent to the host machine, creating a high-risk environment if an attacker gains code execution. The mount utility, when executed within such a context, allows an adversary to attach host file systems to the container's namespace. This capability is frequently abused for container escapes and host-level privilege escalation. Monitoring the execution of mount within containers marked with container.security_context.privileged == true provides a critical defensive signal against unauthorized host file access. Defenders should establish a baseline for legitimate administrative, backup, and monitoring processes that require mounting operations to minimize noise and improve signal fidelity in containerized production environments.
Impact
Successful exploitation of this technique permits an attacker to bridge the isolation between the container and the host OS. This can lead to the exfiltration of sensitive configuration files, credentials, or system binaries, ultimately resulting in full host compromise and the potential for lateral movement within the infrastructure.
Recommendation
- Deploy the provided EQL detection logic to identify
mountexecution within privileged containers. - Audit all containers currently running with the
privilegedsecurity context and enforce the principle of least privilege by stripping unnecessary capabilities. - Isolate containers that trigger this alert to prevent potential unauthorized access to host file systems during investigation.
- Implement exception lists in your SIEM/detection platform for known, legitimate maintenance or monitoring tasks that perform valid mounting operations.
Immediate actions
Deploy process-creation detection for mount execution in privileged containers
Threat Hunt
Identify all running containers with privileged security context
Data: Container runtime configuration logs