
kube-knark
Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

A Blazing fast Security Auditing tool for Kubernetes

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Automated container orchestration tool for Browser-in-the-Browser (BITB) phishing attacks, enabling red teams to scale multi-target infrastructure…

Port Scanner with Docker & Prometheus + Grafana integration. A tool for network auditing with multithreading support and real-time monitoring.

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

A tool to scan Kubernetes cluster for risky permissions

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Gorsair gives root access on remote docker containers that expose their APIs

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…


Docker container for CVE-2015-8103 exploitation targeting JBoss, part of a vulnerable container management framework for security testing.

CLI tool that explains CVEs in plain English and scans repos for impact. Powered by Claude.

Docker container with CVE-2015-5602 for practicing privilege escalation in a controlled environment. Part of the Cved framework for managing…

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

Docker container providing a vulnerable Apache Struts2 environment for CVE-2018-11776 exploitation practice and security education.