Detection: selection: Image|startswith:
'/dev/shm/' condition:selection Falsepositives:
-Unlikely in production environments; some container runtimes or IPC frameworks may use /dev/shm for inter-process communication but should not spawn executables. Level:high