
Persistnux
Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Run iOS apps without actually installing them!

A Linux Host-based Intrusion Detection System based on eBPF.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

In this project, we found a recent attack through the malicious container and implemented a security mechanism to stop it.

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

A vulnerability scanner for container images and filesystems

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…

Security risk analysis for Kubernetes resources

Proof of concept code for Datadog Security Labs referenced exploits.

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Isolate your big brother apps https://secure-system.gitlab.io/Insular/
