
iron-proxy
An egress firewall for untrusted workloads.

An egress firewall for untrusted workloads.

Scans Docker Hub images using regex patterns to extract exposed secrets, private keys, and authentication tokens for security auditing and incident…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

POC for CVE-2020-10665 Docker Desktop Local Privilege Escalation

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Kubernetes driver extension of the Chaos Toolkit probes and actions API

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

AndroSH No-Root Multi-Distro Linux on Android via Shizuku/ADB - Run Arch, Fedora, Alpine, Debian, Ubuntu, Kali, Void, Manjaro, OpenSUSE & Chimera…

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides…

SambaCry exploit and vulnerable container (CVE-2017-7494)

☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud

Kubernetes Security Training Platform - focusing on security mitigation