
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Peirates - Kubernetes Penetration Testing tool

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Unauthenticated RCE exploit for Kestra via auth-bypass; creates malicious flows to execute arbitrary OS commands, with options for reverse shells,…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

Exploit tool for CVE-2025-9074, enabling unauthorized Docker API access for container escape, host file read/write, and arbitrary command execution…

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

A tool that shows detailed information about named pipes in Windows

Executes arbitrary commands in Docker containers or Linux namespaces via LD_PRELOAD injection, ideal for penetration testing and red teaming.

A container analysis and exploitation tool for pentesters and engineers.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Go-based remote code execution exploit for CVE-2021-21978 targeting VMware View Planner 4.X, enabling arbitrary file upload and command execution…