容器逃逸配置排查
io.github.mukul975/Anthropic-Cybersecurity-Skills/performing-container-escape-detection
使用 Kubernetes Python 客户端审计容器与 pod 配置中可能助逃逸的错误配置——特权标志、危险能力授予、host path 挂载、共享 namespace,以及 CVE-2022-0492 式的 cgroup 滥用。适用于全集群扫描可能逃逸的工作负载、产出安全态势报告,或在开启强制执行前检查配置。关键词:privileged、hostPath、hostPID、capabilities、CVE-2022-0492、cgroup、kubernetes python client、态势审计。不要用于基于 syscall 的运行时检测——那用 detecting-container-escape-attempts。