
kube-reaper
Scans Kubernetes clusters from any identity, flags dangerous permissions, and chains them into multi-step escalation paths to cluster compromise.

Scans Kubernetes clusters from any identity, flags dangerous permissions, and chains them into multi-step escalation paths to cluster compromise.

Explain why a Linux TCP port may or may not be reachable

eBPF-based Linux agent that enforces executable-level access policies in kernel space, sandboxing processes and restricting file, network, and GPU…

DaemonSet для митигации уязвимости CVE-2026-31431 (Copy Fail)

Proof-of-concept exploit for CVE-2026-78122, demonstrating container filesystem and environment variable exfiltration through docker-socket-proxy's…

Generates SCAP, Ansible, Bash, and CEL security content for compliance evaluation and automated hardening across Linux hosts, containers, and…

A collection of awesome security hardening guides, tools and other resources

Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploitability…

System utility that identifies and restarts daemons using outdated libraries after package upgrades to maintain security. Supports containers and…

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Junior Backend Candidate Exercise: Packaging the dasel CLI (v3.3.1) with Melange, fixing CVE-2026-33320, and building a minimal container image using…

Hardened dasel v3.3.1 package and image built via Melange and apko. Patching CVE-2026-33320.

Educational environment for LTAT.04.022 Homework 4.

This repository contains the scanner component for Greenbone Community Edition.

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

OPA Gatekeeper-based policy templates to mitigate CVE-2020-8554 by restricting Kubernetes Service external IPs to an allow list, preventing traffic…

Detection script for CIFSwitch - CVE-2026-46243