
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

getshell test

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

C-based PoC for CVE-2019-5736

Container escape proof-of-concept exploits for CVE-2026-80521 and CVE-2026-52910, with a disposable QEMU/Ubuntu VM harness for safe PoC execution.

📦 Make security testing of K8s, Docker, and Containerd easier.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Peirates - Kubernetes Penetration Testing tool

Modified version of CVE-2019-5736-PoC by Frichetten

* React2Shell-CVE-2025-55182

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Container escape on any docker container with healthcheck enabled via CVE-2026-31431