
log4shell_sentinel
A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner

A tool to scan Kubernetes cluster for risky permissions

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

Automated container orchestration tool for Browser-in-the-Browser (BITB) phishing attacks, enabling red teams to scale multi-target infrastructure…

Docker container for CVE-2015-8103 exploitation targeting JBoss, part of a vulnerable container management framework for security testing.

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

A tool for exploring each layer in a docker image

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

A container analysis and exploitation tool for pentesters and engineers.

Black-box Kubernetes attack surface discovery tool that probes for unsecured clusters, exposed dashboards, and misconfigurations using…

Pentester-focused Docker registry tool to enumerate and pull images

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Docker container providing a vulnerable Apache Struts2 environment for CVE-2018-11776 exploitation practice and security education.

Docker container providing a vulnerable environment for CVE-2019-10678, designed for security training and exploitation practice within the Cved…

Docker-based vulnerable environment for CVE-2017-8046 Spring framework remote code execution exploit, part of the Cved vulnerable container…

Docker-based vulnerable environment for CVE-2018-15473 exploitation, part of the Cved framework for managing and testing against known…

Docker container providing a vulnerable Apache Tomcat environment for CVE-2017-12615 exploitation, enabling hands-on practice of PUT method file…