Linux Suspicious Privileged Container Execution — Detection Rule
The following analytic detects the execution of a Docker container with the privileged flag set, or with the pid namespace set to the host. This can indicate a container running with elevated permissions and access to the underlying system. Actors can hide containers such as this to enable persistent access.