
kata-containers
Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Peirates - Kubernetes Penetration Testing tool

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Validation of best practices in your Kubernetes clusters

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

A vulnerability scanner for container images and filesystems

CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP

Run iOS apps without actually installing them!

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

Proof of concept code for Datadog Security Labs referenced exploits.

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

Exploits CVE-2026-41567 Docker escape using trojanized xz/unpigz binaries to gain a root shell on the host from inside a container.

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.