
syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

d(ockerp)wn - a docker pwn tool manager

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

A vulnerability scanner for container images and filesystems

A tool to scan Kubernetes cluster for risky permissions

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

A tool for exploring each layer in a docker image

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Low-level unprivileged sandboxing tool used by Flatpak and similar projects

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Chaos testing, network emulation, and stress testing tool for containers

Peirates - Kubernetes Penetration Testing tool

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

A Blazing fast Security Auditing tool for Kubernetes

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.