
gvisor
Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Validation of best practices in your Kubernetes clusters

Hunt for security weaknesses in Kubernetes clusters

Security risk analysis for Kubernetes resources

Exploit for CVE-2019-5736: runc container escape that overwrites host docker-runc binary with a payload, triggered via docker exec.

DaemonSet для митигации уязвимости CVE-2026-64564 (SCTPhantom)