Container Escape Telemetry, Part 6: TeamPCP and What the Lab Predicted
A real threat actor is doing exactly what our lab scenarios simulate. Mapping TeamPCP's container escape kill chain against Tetragon, Falco, and Tracee telemetry to answer: would these tools have caught it?
<p>This is Part 6 of the container escape telemetry series (<a href="../intro">overview</a>). Parts <a href="../isolation">1</a>-<a href="../tuning">5</a> covered isolation primitives, methodology, per-scenario telemetry, production considerations, and tuning. This post takes the lab findings and pressure-tests them against a real threat actor operating in the wild right now.</p>
