
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

📦 Make security testing of K8s, Docker, and Containerd easier.

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

A collection of manifests that will create pods with elevated privileges.

A container analysis and exploitation tool for pentesters and engineers.

PoC for CVE-2019-5736

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

A Linux Host-based Intrusion Detection System based on eBPF.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)


CVE-2019-5736 POCs

PoC and Detection for CVE-2024-21626

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492