Back to Skills

container-escape-techniques

Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via privileged mode, capabilities, Docker socket, cgroup abuse, namespace tricks, or runtime vulnerabilities.

1,311stars179forksUpdated 7/8/2026

Security Assessment

Critical Risk(0/100)

Detected risks:

Destructive Operations([SKILL.md] fdisk, [DOCKER_ESCAPE_CHAINS.md] fdisk)
Persistence([DOCKER_ESCAPE_CHAINS.md] authorized_keys, [DOCKER_ESCAPE_CHAINS.md] crontab)
Secret Exposure([DOCKER_ESCAPE_CHAINS.md] TOKEN=)
Sensitive File Access([SKILL.md] /etc/shadow, [DOCKER_ESCAPE_CHAINS.md] .ssh/, [DOCKER_ESCAPE_CHAINS.md] /etc/shadow)
Security Score0/100

About container-escape-techniques

An offensive-security playbook for breaking out of Docker containers, LXC, and Kubernetes pods to the underlying host, intended for authorized penetration testing. It applies once an operator is inside a container and needs to reach the host through misconfiguration or capability abuse, and it routes to related privilege-escalation, Kubernetes-pentesting, and security-bypass material as needed. It opens with container detection using /proc/1/cgroup, /.dockerenv, mountinfo, and tools such as amicontained, deepce, and CDK.

Escape paths are grouped by root cause. Privileged containers allow mounting the host disk (for example /dev/sda1) and using nsenter --target 1 to enter host namespaces for an effective host shell, and with hostPID the host filesystem is reachable through /proc/1/root. Capability abuse covers CAP_SYS_ADMIN for mount-based escapes, CAP_SYS_PTRACE for process injection, CAP_NET_ADMIN for host network manipulation, and CAP_DAC_READ_SEARCH via the shocker open_by_handle_at technique. A mounted Docker socket enables creating a privileged container through the CLI or the raw HTTP API with curl.

Further sections detail the cgroup v1 release_agent escape for CAP_SYS_ADMIN with cgroup v1, considerations for cgroup v2 and eBPF, and namespace escapes via unshare and shared PID namespaces. Runtime vulnerabilities include runc CVE-2019-5736, containerd CVE-2020-15257, and cgroups CVE-2022-0492. A Kubernetes pod-escape matrix maps dangerous pod specs (hostPID, hostNetwork, hostPath mounting root, privileged, and over-privileged service-account tokens) to their escapes, and a tool table lists deepce, CDK, amicontained, PEIRATES, and BOtB. Presented factually, the same knowledge informs defenders hardening container platforms.

FAQ

How do I tell whether I'm inside a container?

Check /proc/1/cgroup for docker, kubepods, or containerd, look for /.dockerenv, inspect mountinfo for an overlay filesystem, or run amicontained, deepce, or CDK.

What does a privileged container make possible?

Mounting the host disk such as /dev/sda1 and entering host namespaces with nsenter --target 1 --mount --uts --ipc --net --pid, which yields an effective host shell.

Which capability is described as the most versatile for escape?

CAP_SYS_ADMIN, which enables mount-based escapes such as mounting a cgroup or the host filesystem when device access exists.

Which container runtime CVEs are referenced?

runc CVE-2019-5736 (overwrites the host runc binary on docker exec), containerd CVE-2020-15257 (abstract Unix socket with shared host network), and cgroups CVE-2022-0492.

Which Kubernetes pod specs enable escape?

hostPID true, hostNetwork true, hostPath mounting /, privileged true, and a service-account token with permissive RBAC that can create a new privileged pod.

All Files

2 files
SKILL.md9.1 KB
View
DOCKER_ESCAPE_CHAINS.md8.9 KB
View

Install container-escape-techniques

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill