Check Group Membership
docker or lxd group → root escalation possible.
Docker Privesc
Mount Host Filesystem
Alternative Images
If No Internet (Use Local Image)
Read Sensitive Files
Add SSH Key to Root
Create SUID bash
Docker Socket Abuse
If/var/run/docker.sock is accessible: