Container Escape Advanced
Course Description
Go beyond basic escapes. Learn advanced container breakout techniques targeting kernel, cgroups, and orchestrators.
Course Structure
Modules
Module 1: Container Internals (6h)
- Namespace deep dive
- cgroups internals
- seccomp profiles
- AppArmor/SELinux
- Capabilities system
Module 2: Kernel Exploitation (8h)
- Kernel vulnerabilities
- Container kernel exploits
- Dirty COW/Pipe variants
- eBPF exploitation
Module 3: cgroups Escape (6h)
- cgroups v1 attacks
- cgroups v2 attacks
- Release agent abuse
- Notify on release
Module 4: Namespace Attacks (5h)
- User namespace abuse
- PID namespace escape
- Network namespace attacks
- Mount namespace abuse
Module 5: Advanced K8s (6h)
- CRI exploitation
- Kubelet attacks
- etcd compromise
- Admission webhook bypass
Module 6: Service Mesh (5h)
- Istio attacks
- Envoy exploitation
- mTLS bypass
- Sidecar abuse
Module 7: Cloud Containers (4h)
- ECS/EKS attacks
- AKS exploitation
- GKE attacks
- Serverless containers
Tools
| Tool | Purpose |
|---|---|
| deepce | Enumeration |
| CDK | Container toolkit |
| Peirates | K8s attacks |
| kube-hunter | Scanning |
📄️ Overview
Advanced container breakout: kernel exploits, cgroups abuse, and orchestrator attacks