Sigma Rule Library

MITRE ATT&CK technique

Escape to Host detection rulesT1611

Escape to Host (T1611) is a MITRE ATT&CK technique in the Privilege Escalation tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1611 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target kubernetes.

Top products

Tactic