
CVE-2026-21008-Kubernetes-Service-Account-Token-Mounted-in-HostPath
Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

PoC helper scripts and Dockerfile for CVE-2019-1002101

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Java client library for the Kubernetes API, enabling programmatic management of clusters, pods, deployments, and other resources with support for…

The easiest, and most secure way to access and protect all of your infrastructure.

A collection of awesome security hardening guides, tools and other resources

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

SambaCry exploit and vulnerable container (CVE-2017-7494)

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)

Proof of concept for CVE-2020-15257 in containerd.

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

Proof-of-concept exploit for CVE-2023-36723, an arbitrary directory creation vulnerability in Windows Container Manager, enabling privilege…