Severity: **medium**. Verify the event genuinely matches the described behavior and not a known legitimate operation.
ATT&CK technique(s): T1548.001. Depending on the technique: container escape, privilege escalation, persistence or credential access? Look for the matching indicators in the event.
⚠️ No automatic action. Network isolation of the pod, recreation from a clean image, rotation of exposed secrets — to be decided by a human.