
pulsar-docker-images-patch-CVE-2021-44228
Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell

Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

mailcow: Docker Container Exposure to Local Network

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

A collection of manifests that will create pods with elevated privileges.

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster


Issue with AWS SAM CLI (CVE-2025-3047, CVE-2025-3048)

Go-based Kubernetes exploitation tool that scans for exposed ports and exploits cluster misconfigurations, including anonymous Kubelet RCE and etcd…

Black-box Kubernetes attack surface discovery tool that probes for unsecured clusters, exposed dashboards, and misconfigurations using…

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Kubolt utility for scanning public kubernetes clusters


Pentester-focused Docker registry tool to enumerate and pull images

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…