
kingfisher
Detect secrets + live validation. Map blast radius. Revoke fast. Use the CLI or embed in Rust and Python.

Detect secrets + live validation. Map blast radius. Revoke fast. Use the CLI or embed in Rust and Python.

Proof-of-concept lab and Python/cURL scripts demonstrating CVE-2026-20896, an authentication bypass in official Gitea Docker images via the…

Explain why a Linux TCP port may or may not be reachable

Kubernetes driver extension of the Chaos Toolkit probes and actions API

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

PoC for Docker `docker cp` arbitrary file write, exploiting symlink and tar extraction flaws to overwrite host binaries or launch agents for…

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

Sudo <= 1.8.14 Local Privilege Escalation and vulnerable container

Sudo 1.6.x <= 1.6.9p21 and 1.7.x <= 1.7.2p4 Local Privilege Escalation and vulnerable container

PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution

Proof of Concept exploit for Kubernetes CVE-2020-8559


Docker environment and exploit the CVE-2023-30212 vulnerabilityVE-2023-30212 is a security vulnerability that affects versions of OURPHP prior to or…

Docker-based lab environment to exploit CVE-2023-30212, a cross-site scripting (XSS) vulnerability in OURPHP <= 7.2.0, with step-by-step setup and…