
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

📦 Make security testing of K8s, Docker, and Containerd easier.

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

A collection of manifests that will create pods with elevated privileges.

A container analysis and exploitation tool for pentesters and engineers.

PoC for CVE-2019-5736

A Linux Host-based Intrusion Detection System based on eBPF.

Proof of concept code for Datadog Security Labs referenced exploits.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

An exploit primitive in linux kernel inspired by DirtyPipe
