#1Tools for assessing, testing, and securing cloud environments (AWS, Azure, GCP) and their services.
Kitploit recommended

PoC exploit for insecure permissions in Contour v1.28.3 that retrieves a Kubernetes service account token and accesses the cluster API, demonstrating…
Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

A little demonstration of cve-2021-41773 on httpd docker containers

Docker-based lab environment for CVE-2021-41773 (Apache HTTP Server 2.4.49) path traversal and RCE exploitation with step-by-step setup instructions.

In this project, we found a recent attack through the malicious container and implemented a security mechanism to stop it.

Issue with AWS SAM CLI (CVE-2025-3047, CVE-2025-3048)

A tool to manage vulnerable docker containers

Python-based scanner that checks Docker hosts for CVE-2024-41110 by detecting vulnerable Docker versions and AuthZ plugin usage.

IngressNightmare (CVE-2025-1974)

Test environments for CVE-2023-28432, information disclosure in MinIO clusters

reproducing an old istio bug

An Ansible Playbook to mitigate the risk of RCE (CVE-2024-6387) until platforms update OpenSSH to a non-vulnerable version.

Proof-of-concept for CVE-2024-21626, a container escape vulnerability in runc, demonstrating exploitation techniques.

Remediation task for CVE-2018-15686, CVE-2018-16866, and CVE-2018-16888 affecting SystemD in EL7

OPA Gatekeeper constraint policy that detects and prevents Kubernetes clusters from being vulnerable to CVE-2020-8554, enforcing secure configuration.

cve-2019-5420

A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary…

Ansible playbook for patching CVE-2024-3094