
legion
Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance…

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

d(ockerp)wn - a docker pwn tool manager

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

A vulnerability scanner for container images and filesystems

A tool to scan Kubernetes cluster for risky permissions

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

A tool for exploring each layer in a docker image

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Low-level unprivileged sandboxing tool used by Flatpak and similar projects

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Chaos testing, network emulation, and stress testing tool for containers

Peirates - Kubernetes Penetration Testing tool

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…