CARBONATO Unauthenticated Docker Registry Access and Implant Image Pull

Detects unauthorized access to unauthenticated Docker registry API endpoints on port 5000. This rule identifies catalog enumeration and the pulling of malicious container images associated with the CARBONATO botnet, including the retrieval of image manifests and configuration files that expose sensitive environment variables and credentials.