
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

Exploit for CVE-2026-31431, a Linux kernel page-cache write primitive enabling local privilege escalation and container escape via AF_ALG and…

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

getshell test

Go-based exploit for CVE-2019-5736 (Runc container escape) with a customizable reverse shell payload, designed for penetration testing and red team…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Peirates - Kubernetes Penetration Testing tool

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Run iOS apps without actually installing them!

* React2Shell-CVE-2025-55182

CVE-2022-0185