
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

📦 Make security testing of K8s, Docker, and Containerd easier.

Peirates - Kubernetes Penetration Testing tool

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

Red Team K8S Adversary Emulation Based on kubectl

A container analysis and exploitation tool for pentesters and engineers.

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

eBPF-based stealth container that hides processes, sockets, eBPF objects, and audit logs from system monitoring tools, enabling covert…

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

A collection of scripts, and tips and tricks for hacking k8s clusters and containers.

Linux privilege escalation via LXD

Post-exploit a compromised etcd, gain persistence and remote shell to nodes.

This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…