
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

getshell test

Modified version of CVE-2019-5736-PoC by Frichetten

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Peirates - Kubernetes Penetration Testing tool

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Security risk analysis for Kubernetes resources

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

Validation of best practices in your Kubernetes clusters

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…