📑 Table of Contents
🎯 Overview
DockerScan v2.0 is a next-generation security scanner for Docker containers and images, completely rewritten in Go. It combines multiple security scanning techniques based on the latest 2024-2025 research, industry standards (CIS Benchmark, NIST SP 800-190), and real-world attack patterns discovered in production environments.
Why DockerScan v2.0?
- ✅ Most Comprehensive: Combines 5+ security scanning techniques in one tool
- ✅ Latest Research: Based on 2024-2025 supply chain attacks and CVEs
- ✅ Production Ready: SARIF output for CI/CD, exit codes for automation
- ✅ Blazing Fast: Written in Go with concurrent scanning
- ✅ Extensible: Plugin architecture for custom scanners
- ✅ Free & Open Source: BSD-3 license
🌟 Features
🛡️ Security Scanning Modules
1. CIS Docker Benchmark v1.7.0
Complete compliance checking with 80+ automated controls:
- ✅ Host configuration security (13 checks)
- ✅ Docker daemon hardening (18 checks)
- ✅ File & directory permissions (9 checks)
- ✅ Container image best practices (13 checks)
- ✅ Runtime security validation (31+ checks)
- ✅ Security operations compliance
2. Supply Chain Attack Detection 🆕
Based on real 2024 attack campaigns:
- ✅ Imageless Container Detection - Identifies malicious containers with no actual layers (4M+ found on Docker Hub)
- ✅ Cryptocurrency Miner Detection - Detects mining malware (120K+ malicious image pulls detected)
- ✅ Backdoored Library Detection - Catches compromised dependencies (xz-utils, liblzma incidents)
- ✅ Image Signature Verification - Validates signatures using Notary/Cosign
- ✅ Phishing Content Detection - Scans documentation for social engineering
- ✅ Malicious Network Destinations - Identifies C2 servers, mining pools, Tor nodes
3. Advanced Secrets Detection 🔑
40+ secret patterns including modern APIs (2024 update):
- ✅ Cloud Providers: AWS, GCP, Azure credentials
- ✅ Version Control: GitHub, GitLab, Bitbucket tokens
- ✅ AI/ML APIs: OpenAI, Anthropic, Hugging Face keys
- ✅ Payment: Stripe, PayPal, Square keys
- ✅ Communication: Slack, SendGrid, Twilio, Mailchimp
- ✅ Authentication: JWT tokens, OAuth tokens
- ✅ Crypto: Private keys (RSA, SSH, PGP, EC, DSA), certificates
- ✅ Databases: PostgreSQL, MySQL, MongoDB connection strings
- ✅ Docker: Registry authentication tokens
- ✅ Entropy Analysis: Shannon entropy calculation for unknown secrets (>4.5 threshold)
4. CVE & Vulnerability Scanning 🚨
Critical 2024-2025 CVE detection:
- ✅ CVE-2024-21626 - runc container escape (CVSS 8.6)
- ✅ CVE-2024-23651 - BuildKit cache poisoning RCE (CVSS 9.1)
- ✅ CVE-2024-23652 - BuildKit race condition (CVSS 7.5)
- ✅ CVE-2024-23653 - BuildKit privilege escalation
- ✅ CVE-2024-8695/8696 - Docker Desktop RCE (CVSS 8.8)
- ✅ CVE-2025-9074 - Docker Desktop local access vulnerability
- ✅ End-of-life base image detection
- ✅ Known vulnerable package scanning
5. Runtime Security Analysis ⚙️
Container runtime hardening checks:
- ✅ Linux Capabilities Auditing - Detects dangerous capabilities (CAP_SYS_ADMIN, CAP_NET_ADMIN, etc.)
- ✅ Seccomp Profile Validation - Ensures syscall filtering is enabled
- ✅ AppArmor/SELinux Checks - Mandatory access control verification
- ✅ Privileged Container Detection - Identifies containers with full host access
- ✅ Namespace Isolation - PID, IPC, network, user namespace checks
- ✅ Container Escape Indicators - Detects common escape techniques
📊 Reporting & Integration
- JSON - Machine-readable output for automation
- SARIF - Native integration with:
- GitHub Security tab
- Azure DevOps
- VS Code extensions
- GitLab security dashboards
- Beautiful CLI - Color-coded severity levels with emojis
- Exit Codes - CI/CD friendly (0=clean, 1=warnings, 2=critical)
- ⚡ 10x Faster than Python alternatives
- 🔄 Concurrent Scanning with Go goroutines
- 💾 Low Memory footprint (~50-100MB)
- 📦 Single Binary - No dependencies
🆕 What's New in v2.0?
DockerScan v2.0 is a complete rewrite from the ground up. Here's what changed from v1.x:
Major Changes
| Feature | v1.x (Python) | v2.0 (Go) |
|---|
| Language | Python 3.5+ | Go 1.21+ |
| Performance | ~500 images/hour | ~5000 images/hour |
| Memory Usage | 200-500 MB | 50-100 MB |
| Distribution | pip install + deps | Single binary |
| Security Scanners | 2 modules | 5 modules |
| CIS Benchmark | Partial | Full v1.7.0 (80+ checks) |
| Supply Chain | ❌ Not available | ✅ Based on 2024 research |
| Secret Patterns | 10 patterns | 40+ patterns |
| CVE Detection | Basic | 2024-2025 CVEs |
| Runtime Security | ❌ Not available | ✅ Full capabilities audit |
| SARIF Output | ❌ Not available | ✅ Full support |
| CI/CD Integration | Manual | Native (exit codes, SARIF) |
What's Preserved from v1.x
- ✅ Offensive Tools - Image trojanization capabilities (coming soon in v2.1)
- ✅ Registry Operations - Push, pull, delete operations (coming soon in v2.1)
- ✅ Network Scanning - Docker registry discovery (coming soon in v2.1)
New in v2.0.5 🔐