
cve_2019-5736-PoC
C-based PoC for CVE-2019-5736

C-based PoC for CVE-2019-5736
Proof-of-concept exploit for CVE-2022-0847 (DirtyPipe) enabling container breakout via kernel privilege escalation. Includes demonstration and…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Modified version of CVE-2019-5736-PoC by Frichetten

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

📦 Make security testing of K8s, Docker, and Containerd easier.

Validation of best practices in your Kubernetes clusters

Proof of concept code for Datadog Security Labs referenced exploits.

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w…

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

A collection of manifests that will create pods with elevated privileges.

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…