The docker.sock UNIX socket is used by the Docker daemon for the acessing the Docker API. This TTP determines if a Docker socket escape via docker.sock is possible. An attacker may be able to escape the container if the Docker socket is mounted in it.
To view this TTPs command, you must be logged in with a professional or enterprise license.
Escape a Docker container that has the Docker socket mounted.
About PreludePrelude hardens an organization's defenses by continuously “asking” it questions through the form of safe cyberattacks. These attacks respond immediately to the latest vulnerabilities and cyber events, turning complex technical descriptions into deployable “questions”.Our mission is to increase the reach, frequency and usage of advanced security for all organizations.