
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Peirates - Kubernetes Penetration Testing tool

Security risk analysis for Kubernetes resources

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Exposure checker and safe disposable-VM lab for CVE-2026-23111 (Linux nf_tables use-after-free local privilege escalation). Defensive: detection,…

Validation of best practices in your Kubernetes clusters

PoC for Docker `docker cp` arbitrary file write, exploiting symlink and tar extraction flaws to overwrite host binaries or launch agents for…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

📦 Make security testing of K8s, Docker, and Containerd easier.