
grapheneX
Automated System Hardening Framework

Automated System Hardening Framework

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

Automated Kubernetes cluster penetration testing tool that exploits misconfigurations in API, Kubelet, etcd, and Dashboard to achieve node takeover…

Step-by-step tutorial for detecting CVE-2024-3094 (XZ Backdoor) in container images using Trend Micro Vision One TMAS CLI, with automated scanning…

A container image that exfiltrates the underlying container runtime to a remote server

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

One-liner scripts to check server and Docker image vulnerability to CVE-2024-3094, including version detection and repository scanning for xz…

PoC dockerfile image for CVE-2025-48384

Grafana image with DuckDB binary present vulnerable to exploit CVE-2024-9264

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Minimal CVE Hardened container image collection

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

Puppet module to harden ImageMagick policy.xml against CVE-2016-3714 by restricting dangerous image processing directives.

Exploit for CVE-2013-0212 targeting OpenStack Glance image service. Demonstrates authentication bypass vulnerability for security testing and…

Pentester-focused Docker registry tool to enumerate and pull images

Kubernetes Lab for CVE-2022-42889