
ingress-nginx
Ingress NGINX Controller for Kubernetes

Ingress NGINX Controller for Kubernetes

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

CVE-2020-8554: Man in the middle using LoadBalancer or ExternalIPs

Proof-of-concept exploit for CVE-2020-10749 demonstrating Kubernetes MitM attacks via IPv6 rogue router advertisements between pods.

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

A Microservices-based framework for the study of Network Security and Penetration Test techniques

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

An egress firewall for untrusted workloads.

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

Docker-based CVE-2018-10933 libssh authentication bypass exploit with patched client for testing SSH server vulnerabilities and unauthorized access…

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Information about Kubernetes CVE-2020-8558, including proof of concept exploit.

BPF-LSM mitigation for CVE-2026-31431 (Copy Fail) — denies AF_ALG socket creation cluster-wide