Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
dockerscan — The Most Comprehensive Docker Security Scanner | Kitploit
Tools/GitHubGitHub/cr0hn/dockerscan
Vulnerability ScannersContainer SecurityConfiguration AuditingCloud SecurityDevSecOpsSecret DetectionSupply Chain Security
GitHubcr0hn/dockerscan

dockerscan

The Most Comprehensive Docker Security Scanner

View Repository
1.7k2472617h 21m agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
DockerScan Logo

DockerScan v2.0

The Most Comprehensive Docker Security Scanner

License Go Version Version CI/CD Test Coverage Go Report Card Downloads

By Daniel Garcia (cr0hn) | GitHub | Website


Features • Installation • Quick Start • Documentation • Use Cases • What's New • Contributing


📑 Table of Contents

  • Overview
  • Features
  • What's New in v2.0
  • Installation
  • Quick Start
  • Usage
    • Private Registry Authentication
  • Security Scanners
  • Output Formats
  • Use Cases
  • Comparison
  • Architecture
  • Contributing
  • References
  • License
  • Author

🎯 Overview

DockerScan v2.0 is a next-generation security scanner for Docker containers and images, completely rewritten in Go. It combines multiple security scanning techniques based on the latest 2024-2025 research, industry standards (CIS Benchmark, NIST SP 800-190), and real-world attack patterns discovered in production environments.

Why DockerScan v2.0?

  • ✅ Most Comprehensive: Combines 5+ security scanning techniques in one tool
  • ✅ Latest Research: Based on 2024-2025 supply chain attacks and CVEs
  • ✅ Production Ready: SARIF output for CI/CD, exit codes for automation
  • ✅ Blazing Fast: Written in Go with concurrent scanning
  • ✅ Extensible: Plugin architecture for custom scanners
  • ✅ Free & Open Source: BSD-3 license

🌟 Features

🛡️ Security Scanning Modules

1. CIS Docker Benchmark v1.7.0

Complete compliance checking with 80+ automated controls:

  • ✅ Host configuration security (13 checks)
  • ✅ Docker daemon hardening (18 checks)
  • ✅ File & directory permissions (9 checks)
  • ✅ Container image best practices (13 checks)
  • ✅ Runtime security validation (31+ checks)
  • ✅ Security operations compliance

2. Supply Chain Attack Detection 🆕

Based on real 2024 attack campaigns:

  • ✅ Imageless Container Detection - Identifies malicious containers with no actual layers (4M+ found on Docker Hub)
  • ✅ Cryptocurrency Miner Detection - Detects mining malware (120K+ malicious image pulls detected)
  • ✅ Backdoored Library Detection - Catches compromised dependencies (xz-utils, liblzma incidents)
  • ✅ Image Signature Verification - Validates signatures using Notary/Cosign
  • ✅ Phishing Content Detection - Scans documentation for social engineering
  • ✅ Malicious Network Destinations - Identifies C2 servers, mining pools, Tor nodes

3. Advanced Secrets Detection 🔑

40+ secret patterns including modern APIs (2024 update):

  • ✅ Cloud Providers: AWS, GCP, Azure credentials
  • ✅ Version Control: GitHub, GitLab, Bitbucket tokens
  • ✅ AI/ML APIs: OpenAI, Anthropic, Hugging Face keys
  • ✅ Payment: Stripe, PayPal, Square keys
  • ✅ Communication: Slack, SendGrid, Twilio, Mailchimp
  • ✅ Authentication: JWT tokens, OAuth tokens
  • ✅ Crypto: Private keys (RSA, SSH, PGP, EC, DSA), certificates
  • ✅ Databases: PostgreSQL, MySQL, MongoDB connection strings
  • ✅ Docker: Registry authentication tokens
  • ✅ Entropy Analysis: Shannon entropy calculation for unknown secrets (>4.5 threshold)

4. CVE & Vulnerability Scanning 🚨

Critical 2024-2025 CVE detection:

  • ✅ CVE-2024-21626 - runc container escape (CVSS 8.6)
  • ✅ CVE-2024-23651 - BuildKit cache poisoning RCE (CVSS 9.1)
  • ✅ CVE-2024-23652 - BuildKit race condition (CVSS 7.5)
  • ✅ CVE-2024-23653 - BuildKit privilege escalation
  • ✅ CVE-2024-8695/8696 - Docker Desktop RCE (CVSS 8.8)
  • ✅ CVE-2025-9074 - Docker Desktop local access vulnerability
  • ✅ End-of-life base image detection
  • ✅ Known vulnerable package scanning

5. Runtime Security Analysis ⚙️

Container runtime hardening checks:

  • ✅ Linux Capabilities Auditing - Detects dangerous capabilities (CAP_SYS_ADMIN, CAP_NET_ADMIN, etc.)
  • ✅ Seccomp Profile Validation - Ensures syscall filtering is enabled
  • ✅ AppArmor/SELinux Checks - Mandatory access control verification
  • ✅ Privileged Container Detection - Identifies containers with full host access
  • ✅ Namespace Isolation - PID, IPC, network, user namespace checks
  • ✅ Container Escape Indicators - Detects common escape techniques

📊 Reporting & Integration

  • JSON - Machine-readable output for automation
  • SARIF - Native integration with:
    • GitHub Security tab
    • Azure DevOps
    • VS Code extensions
    • GitLab security dashboards
  • Beautiful CLI - Color-coded severity levels with emojis
  • Exit Codes - CI/CD friendly (0=clean, 1=warnings, 2=critical)

🚀 Performance

  • ⚡ 10x Faster than Python alternatives
  • 🔄 Concurrent Scanning with Go goroutines
  • 💾 Low Memory footprint (~50-100MB)
  • 📦 Single Binary - No dependencies

🆕 What's New in v2.0?

DockerScan v2.0 is a complete rewrite from the ground up. Here's what changed from v1.x:

Major Changes

Featurev1.x (Python)v2.0 (Go)
LanguagePython 3.5+Go 1.21+
Performance~500 images/hour~5000 images/hour
Memory Usage200-500 MB50-100 MB
Distributionpip install + depsSingle binary
Security Scanners2 modules5 modules
CIS BenchmarkPartialFull v1.7.0 (80+ checks)
Supply Chain❌ Not available✅ Based on 2024 research
Secret Patterns10 patterns40+ patterns
CVE DetectionBasic2024-2025 CVEs
Runtime Security❌ Not available✅ Full capabilities audit
SARIF Output❌ Not available✅ Full support
CI/CD IntegrationManualNative (exit codes, SARIF)

What's Preserved from v1.x

  • ✅ Offensive Tools - Image trojanization capabilities (coming soon in v2.1)
  • ✅ Registry Operations - Push, pull, delete operations (coming soon in v2.1)
  • ✅ Network Scanning - Docker registry discovery (coming soon in v2.1)

New in v2.0.5 🔐

Download Tool