Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vesta — A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing | Kitploit
Tools/GitHubGitHub/kvesta/vesta
Static AnalysisVulnerability ScannersContainer SecurityConfiguration AuditingCloud SecurityDevSecOps
GitHubkvesta/vesta

vesta

A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing

View Repository
20531141 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share


A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing.

English · 简体中文

Overview

Vesta is a static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit. It inspects Kubernetes and Docker configures, cluster pods, and containers with safe practices.

Vesta is a flexible toolkit which can run on physical machines in different types of systems (Windows, Linux, MacOS).

What can vesta check

Scan

  • Support scanning input
    • image
    • container
    • filesystem
    • vm (TODO)
  • Scan the vulnerabilities of major package managements
    • apt/apt-get
    • rpm
    • yum
    • dpkg
  • Scan malicious packages and vulnerabilities of language-specific packages
    • Java(Jar, War. major library: log4j)
    • NodeJs(NPM, YARN)
    • Python(Wheel, Poetry)
    • Golang(Go binary)
    • PHP(Composer, major frameworks: laravel, thinkphp, wordpress, wordpress plugins etc)
    • Rust(Rust binary)
    • Others(Others vulnerable which will cause a potential container escape and check suspicious poison image)

Docker

SupportedCheck ItemDescriptionSeverityReference
✔PrivilegeAllowedPrivileged module is allowed.criticalRef
✔CapabilitiesDangerous capabilities are opening.criticalRef
✔Volume MountMount dangerous location.criticalRef
✔Docker Unauthorized2375 port is opening and unauthorized.criticalRef
✔Kernel versionKernel version is under the escape version.criticalRef
✔Network ModuleNet Module is host and containerd version less than 1.41.critical/medium
✔Pid ModulePid Module is host.high
✔Docker Server versionServer version is included the vulnerable version.critical/high/ medium/low
✔Docker env password checkCheck weak password in database.high/medium
✔Docker HistoryDocker layers and environment have some dangerous commands.high/medium
✔Docker BackdoorDocker env command has malicious commands.critical/high
✔Docker SwarmDocker swarm has dangerous config or secrets or containers are unsafe.medium/low
✔Docker supply chainDocker supply chain has vulnerable configurationscritical/high/ mediumRef

Kubernetes

Download Tool