
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

getshell test

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

C-based PoC for CVE-2019-5736

Container escape proof-of-concept exploits for CVE-2026-80521 and CVE-2026-52910, with a disposable QEMU/Ubuntu VM harness for safe PoC execution.

📦 Make security testing of K8s, Docker, and Containerd easier.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Modified version of CVE-2019-5736-PoC by Frichetten

Peirates - Kubernetes Penetration Testing tool

Docker exploit

POC for CVE-2020-10665 Docker Desktop Local Privilege Escalation

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Container escape on any docker container with healthcheck enabled via CVE-2026-31431

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

A container analysis and exploitation tool for pentesters and engineers.