
k0otkit
Post-penetration Kubernetes cluster manipulation tool using dynamic container injection and encrypted reverse shells for covert, continuous node…

Post-penetration Kubernetes cluster manipulation tool using dynamic container injection and encrypted reverse shells for covert, continuous node…

Unauthenticated RCE exploit for Kestra via auth-bypass; creates malicious flows to execute arbitrary OS commands, with options for reverse shells,…

Android app isolation tool using work profiles to sandbox, freeze, and hide apps, with multi-account cloning and selective VPN routing for privacy.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

A vulnerability scanner for container images and filesystems

Automated Kubernetes penetration testing tool for privilege escalation, service account token theft, secret collection, and cluster pivot attacks…

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

A container analysis and exploitation tool for pentesters and engineers.

A tool that shows detailed information about named pipes in Windows

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Exploit tool for CVE-2025-9074, enabling unauthorized Docker API access for container escape, host file read/write, and arbitrary command execution…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

Executes arbitrary commands in Docker containers or Linux namespaces via LD_PRELOAD injection, ideal for penetration testing and red teaming.

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Go-based remote code execution exploit for CVE-2021-21978 targeting VMware View Planner 4.X, enabling arbitrary file upload and command execution…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…