
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Run iOS apps without actually installing them!

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Security risk analysis for Kubernetes resources

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Proof of concept code for Datadog Security Labs referenced exploits.

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

A Linux Host-based Intrusion Detection System based on eBPF.

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Local privilege escalation exploit for CVE-2026-31431 in the Linux kernel crypto subsystem, providing root access and container breakout with a…

This repository provides a high-fidelity technical deconstruction and production-ready exploitation suite for CVE-2019-5736. It demonstrates how a…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…