
falco
Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Automated Kubernetes penetration testing tool for privilege escalation, service account token theft, secret collection, and cluster pivot attacks…

A container analysis and exploitation tool for pentesters and engineers.

Exploit tool for CVE-2025-9074, enabling unauthorized Docker API access for container escape, host file read/write, and arbitrary command execution…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…