
kubernetes-goat
Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

📦 Make security testing of K8s, Docker, and Containerd easier.

Scan .onion hidden services with nmap using Tor, proxychains and dnsmasq in a minimal alpine Docker container.

The Swiss Army Container for Cloud Native Security. Container with all the list of useful tools/commands while hacking and securing Containers,…

OpenSSH remote DOS exploit and vulnerable container

Proof-of-Concept for CVE-2024-52005: ANSI escape sequence injection in Git. Demonstrates incorrect 'not_affected' VEX claims in hardened container…

Hunt for security weaknesses in Kubernetes clusters

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

Kubernetes Security Training Platform - focusing on security mitigation

A Microservices-based framework for the study of Network Security and Penetration Test techniques

SambaCry exploit and vulnerable container (CVE-2017-7494)

A container analysis and exploitation tool for pentesters and engineers.

Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492

NTPD remote DOS exploit and vulnerable container

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.