
kubescape
Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

👀 A Kubernetes cluster resource sanitizer

Hardened, Azure-optimized Linux distribution built from Fedora sources with RPM packaging, supply chain security, and declarative configuration for…

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

Gorsair gives root access on remote docker containers that expose their APIs

Red Team K8S Adversary Emulation Based on kubectl

PoC for CVE-2019-5736

By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

A repo to automatically generate and keep updated a series of Docker images through GitHub Actions.

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

eBPF-based stealth container that hides processes, sockets, eBPF objects, and audit logs from system monitoring tools, enabling covert…

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Black-box Kubernetes attack surface discovery tool that probes for unsecured clusters, exposed dashboards, and misconfigurations using…

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Firecracker made simple. Spin up secure microVMs in milliseconds, from install to interactive shell in one command.