
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Hunt for security weaknesses in Kubernetes clusters

getshell test

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Exploit for CVE-2026-31431, a Linux kernel page-cache write primitive enabling local privilege escalation and container escape via AF_ALG and…

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

C-based PoC for CVE-2019-5736

Container escape proof-of-concept exploits for CVE-2026-80521 and CVE-2026-52910, with a disposable QEMU/Ubuntu VM harness for safe PoC execution.

📦 Make security testing of K8s, Docker, and Containerd easier.