CARBONATO Worm Docker API Container Create for Propagation
This rule detects unauthorized attempts to create privileged containers via the Docker API, specifically identifying the use of the 'net-setup' string often associated with the CARBONATO worm. Such activity indicates potential propagation or lateral movement within a containerized environment by attempting to deploy containers with elevated permissions.
Suricata

