
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Hunt for security weaknesses in Kubernetes clusters

Security risk analysis for Kubernetes resources

PoC for Dirty COW (CVE-2016-5195)

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

A container analysis and exploitation tool for pentesters and engineers.

Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)

VM Escape for Parallels Desktop <18.1.1

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

PoC and Detection for CVE-2024-21626

Exploit for CVE-2025-1974 targeting ingress-nginx controllers in Kubernetes, enabling container escape via crafted shared object injection and shell…

Exploit for CVE-2021-25741 Kubernetes vulnerability allowing host filesystem mount into pods via race condition, with deployment scripts and…