Back to updates
New releaseJul 20, 2026

dockerscan v2.1.0

The Most Comprehensive Docker Security Scanner

Share
DockerScan Logo

DockerScan v2.0

The Most Comprehensive Docker Security Scanner

License Go Version Version CI/CD Test Coverage Go Report Card Downloads

By Daniel Garcia (cr0hn) | GitHub | Website


Features • Installation • Quick Start • Documentation • Use Cases • What's New • Contributing


📑 Table of Contents


🎯 Overview

DockerScan v2.0 is a next-generation security scanner for Docker containers and images, completely rewritten in Go. It combines multiple security scanning techniques based on the latest 2024-2025 research, industry standards (CIS Benchmark, NIST SP 800-190), and real-world attack patterns discovered in production environments.

Why DockerScan v2.0?

  • ✅ Most Comprehensive: Combines 5+ security scanning techniques in one tool
  • ✅ Latest Research: Based on 2024-2025 supply chain attacks and CVEs
  • ✅ Production Ready: SARIF output for CI/CD, exit codes for automation
  • ✅ Blazing Fast: Written in Go with concurrent scanning
  • ✅ Extensible: Plugin architecture for custom scanners
  • ✅ Free & Open Source: BSD-3 license

🌟 Features

🛡️ Security Scanning Modules

1. CIS Docker Benchmark v1.7.0

Complete compliance checking with 80+ automated controls:

  • ✅ Host configuration security (13 checks)
  • ✅ Docker daemon hardening (18 checks)
  • ✅ File & directory permissions (9 checks)
  • ✅ Container image best practices (13 checks)
  • ✅ Runtime security validation (31+ checks)
  • ✅ Security operations compliance

2. Supply Chain Attack Detection 🆕

Based on real 2024 attack campaigns:

  • ✅ Imageless Container Detection - Identifies malicious containers with no actual layers (4M+ found on Docker Hub)
  • ✅ Cryptocurrency Miner Detection - Detects mining malware (120K+ malicious image pulls detected)
  • ✅ Backdoored Library Detection - Catches compromised dependencies (xz-utils, liblzma incidents)
  • ✅ Image Signature Verification - Validates signatures using Notary/Cosign
  • ✅ Phishing Content Detection - Scans documentation for social engineering
  • ✅ Malicious Network Destinations - Identifies C2 servers, mining pools, Tor nodes

3. Advanced Secrets Detection 🔑

40+ secret patterns including modern APIs (2024 update):

  • ✅ Cloud Providers: AWS, GCP, Azure credentials
  • ✅ Version Control: GitHub, GitLab, Bitbucket tokens
  • ✅ AI/ML APIs: OpenAI, Anthropic, Hugging Face keys
  • ✅ Payment: Stripe, PayPal, Square keys
  • ✅ Communication: Slack, SendGrid, Twilio, Mailchimp
  • ✅ Authentication: JWT tokens, OAuth tokens
  • ✅ Crypto: Private keys (RSA, SSH, PGP, EC, DSA), certificates
  • ✅ Databases: PostgreSQL, MySQL, MongoDB connection strings
  • ✅ Docker: Registry authentication tokens
  • ✅ Entropy Analysis: Shannon entropy calculation for unknown secrets (>4.5 threshold)

4. CVE & Vulnerability Scanning 🚨

Critical 2024-2025 CVE detection:

  • ✅ CVE-2024-21626 - runc container escape (CVSS 8.6)
  • ✅ CVE-2024-23651 - BuildKit cache poisoning RCE (CVSS 9.1)
  • ✅ CVE-2024-23652 - BuildKit race condition (CVSS 7.5)
  • ✅ CVE-2024-23653 - BuildKit privilege escalation
  • ✅ CVE-2024-8695/8696 - Docker Desktop RCE (CVSS 8.8)
  • ✅ CVE-2025-9074 - Docker Desktop local access vulnerability
  • ✅ End-of-life base image detection
  • ✅ Known vulnerable package scanning

5. Runtime Security Analysis ⚙️

Container runtime hardening checks:

  • ✅ Linux Capabilities Auditing - Detects dangerous capabilities (CAP_SYS_ADMIN, CAP_NET_ADMIN, etc.)
  • ✅ Seccomp Profile Validation - Ensures syscall filtering is enabled
  • ✅ AppArmor/SELinux Checks - Mandatory access control verification
  • ✅ Privileged Container Detection - Identifies containers with full host access
  • ✅ Namespace Isolation - PID, IPC, network, user namespace checks
  • ✅ Container Escape Indicators - Detects common escape techniques

📊 Reporting & Integration

  • JSON - Machine-readable output for automation
  • SARIF - Native integration with:
    • GitHub Security tab
    • Azure DevOps
    • VS Code extensions
    • GitLab security dashboards
  • Beautiful CLI - Color-coded severity levels with emojis
  • Exit Codes - CI/CD friendly (0=clean, 1=warnings, 2=critical)

🚀 Performance

  • ⚡ 10x Faster than Python alternatives
  • 🔄 Concurrent Scanning with Go goroutines
  • 💾 Low Memory footprint (~50-100MB)
  • 📦 Single Binary - No dependencies

🆕 What's New in v2.0?

DockerScan v2.0 is a complete rewrite from the ground up. Here's what changed from v1.x:

Major Changes

Featurev1.x (Python)v2.0 (Go)
LanguagePython 3.5+Go 1.21+
Performance~500 images/hour~5000 images/hour
Memory Usage200-500 MB50-100 MB
Distributionpip install + depsSingle binary
Security Scanners2 modules5 modules
CIS BenchmarkPartialFull v1.7.0 (80+ checks)
Supply Chain❌ Not available✅ Based on 2024 research
Secret Patterns10 patterns40+ patterns
CVE DetectionBasic2024-2025 CVEs
Runtime Security❌ Not available✅ Full capabilities audit
SARIF Output❌ Not available✅ Full support
CI/CD IntegrationManualNative (exit codes, SARIF)

What's Preserved from v1.x

  • ✅ Offensive Tools - Image trojanization capabilities (coming soon in v2.1)
  • ✅ Registry Operations - Push, pull, delete operations (coming soon in v2.1)
  • ✅ Network Scanning - Docker registry discovery (coming soon in v2.1)

New in v2.0.5 🔐

Categories