ESA SPACE-SHIELD
T1611

Escape to Host

Description

If containers or hypervisors are used, an attacker could overcome the container fences and gain access to the host system. Separations between applications may be defeated, and malicious operations could affect other functionalities. This attack can leverage common utilities, schedulers, shared memory, or vulnerabilities. (Citation: European Space Agency) "Gaining access to the host may provide the adversary with the opportunity to achieve follow-on objectives, such as establishing persistence, moving laterally within the environment, or setting up a command-and-control channel on the host." (Citation: MITRE ATT&CK)

Mapped SPARTA techniques

1 techniques

  • LM-0005Virtualization EscapeST0007
    addresses
    high

    T1611 'Escape to Host' explicitly covers overcoming container/hypervisor fences to gain host access — direct match to LM-0005's virtualization escape from less-trusted partition to higher-privilege domain.

Cite as SafeMode Space, space-shield T1611.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.