
kubesploit
Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

This project is exploit for some docker containers with similar to vulnerability code: CVE-2020-35191

fork on Betep0k/CVE-2021-25741/fork whose images is useless and test on metarget

📦 Make security testing of K8s, Docker, and Containerd easier.

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

A container analysis and exploitation tool for pentesters and engineers.


Kestra Unauthenticated RCE Exploit (CVE-2026-53576)