
starboard
Superseded by https://github.com/aquasecurity/trivy-operator

Superseded by https://github.com/aquasecurity/trivy-operator

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

A container-based framework to enable the integration of mobile components in security training platforms

Cryptographically signed, replay-verifiable evidence layer for AI agents. Governs actions in the loop, produces Ed25519-signed receipts linked into a…

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

Like Envoy xDS, but for eBPF filters

Post-exploit a compromised etcd, gain persistence and remote shell to nodes.

Millisecond microVM sandbox forking for AI agents on Kubernetes. Firecracker VMs that restore from memory snapshots in milliseconds, fork a running…

Deploy a FullStack Prodo-Typing Agent into your AWS Account (OpenClaw, Kiro-Cli, Pi, Hermes, Claude Code, Codex)

Cloud-native system telemetry pipeline that collects, processes, and exports system call events into a compact object-relational format for…

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

CVE-2021-40438 exploit PoC with Docker setup.

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner