
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Hunt for security weaknesses in Kubernetes clusters

Security risk analysis for Kubernetes resources

A container analysis and exploitation tool for pentesters and engineers.

Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

PoC and Detection for CVE-2024-21626

Proof-of-concept container escape exploit targeting CVE-2026-31431 in runC, demonstrating privilege escalation and namespace breakout for security…

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Exploit for CVE-2019-5736: runc container escape that overwrites host docker-runc binary with a payload, triggered via docker exec.

Proof of concept for CVE-2020-15257 in containerd.

Proof-of-concept exploit for CVE-2022-39253 demonstrating Docker container escape via malicious Git repository build, enabling host file system read…