
tetragon
eBPF-based Security Observability and Runtime Enforcement

eBPF-based Security Observability and Runtime Enforcement

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

📦 Make security testing of K8s, Docker, and Containerd easier.

Kubernetes-native security operator that automates vulnerability scanning, configuration auditing, secret detection, RBAC analysis, and compliance…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

A Blazing fast Security Auditing tool for Kubernetes

The Swiss Army Container for Cloud Native Security. Container with all the list of useful tools/commands while hacking and securing Containers,…

Making containers more secure with eBPF and Linux Security Modules (LSM)

Cloud-native system telemetry pipeline that collects, processes, and exports system call events into a compact object-relational format for…

eBPF-based runtime security agent for Kubernetes that detects unknown processes and file changes, enforces pre-registered constraints, and automates…

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

Hands-on lab demonstrating Kubernetes container hardening by comparing default vs. security-enhanced deployments of a vulnerable note-taking…