
kube-linter
KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

A container analysis and exploitation tool for pentesters and engineers.

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

CVE-2021-21978 exp

Proof-of-concept exploit for CVE-2026-5555, demonstrating container escape via /proc/self/fd symlink in rshared volumes to overwrite host files and…

High Severity LPE vulnerability in Linux Kernel, with a CVS score of 7.8. An inverted check from user enables a process inside the container to break…

In this project, we found a recent attack through the malicious container and implemented a security mechanism to stop it.

Container escape on any docker container with healthcheck enabled via CVE-2026-31431

A Linux Host-based Intrusion Detection System based on eBPF.

A tool that shows detailed information about named pipes in Windows

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Proof-of-concept exploit for CVE-2024-21626, a runc container escape vulnerability allowing host file system access via crafted working directory in…

Reproduction of CVE-2017-5123 kernel vulnerability allowing local privilege escalation via waitid syscall memory write, demonstrated with Docker…

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

CVE-2019-5736 implemented in a self-written container runtime to understand the exploit.