Skip to content
View mattreduce's full-sized avatar
🏎️
🏎️

Organizations

@hashicorp @hashivim @MythicAgents @srcmtd

Block or report mattreduce

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

πŸ“¦ container-security

36 repositories

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Shell 281 51 Updated Aug 30, 2021

Cloud Native Runtime Security

C++ 7,495 909 Updated Dec 23, 2024

A curated list of awesome Kubernetes security resources

908 121 Updated Dec 15, 2023

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable packages on the container

Python 154 31 Updated Jun 9, 2023

Moved to https://github.com/aquasecurity/trivy-operator

Go 1,360 197 Updated Dec 11, 2024

An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster

Go 443 62 Updated Dec 23, 2024

A tool for exploring each layer in a docker image

Go 48,723 1,819 Updated Jul 15, 2024

The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

Shell 9,204 1,021 Updated Oct 21, 2024

Checklist for container security - devsecops practices

1,537 221 Updated Sep 29, 2023

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground πŸš€

HTML 4,554 731 Updated Dec 7, 2024

A tool to help forensicate offline docker acquisitions

Python 533 46 Updated Oct 4, 2024

Slides and code samples for training, tutorials, and workshops about Docker, containers, and Kubernetes.

Shell 3,668 1,597 Updated Dec 12, 2024

A Microservices-based framework for the study of Network Security and Penetration Test techniques

JavaScript 582 108 Updated Sep 25, 2024

Low-level unprivileged sandboxing tool used by Flatpak and similar projects

C 4,025 239 Updated Oct 30, 2024

Hardening a sketchy containerized application one step at a time

Go 54 7 Updated Jan 25, 2022

Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.

Go 160 16 Updated Oct 31, 2023

πŸ‘€ A Kubernetes cluster resource sanitizer

Go 5,363 290 Updated Dec 27, 2024

BadRobot - Operator Security Audit Tool

Go 216 4 Updated Dec 23, 2024

A best practices checker for Kubernetes clusters. 🀠

Go 550 45 Updated Sep 6, 2024

Kubernetes exploitation tool

Go 359 22 Updated Jul 26, 2024

A tool to perform Kerberos pre-auth bruteforcing

Go 2,716 422 Updated Aug 20, 2024

A command-line tool to perform Local Health Check Probes inside Container Images (ECS, Docker)

Go 49 2 Updated Nov 10, 2024

Kubernetes offensive framework built in eBPF

C 36 2 Updated Mar 14, 2023

A curated list of resources about detecting threats and defending Kubernetes systems.

369 33 Updated Sep 2, 2023

All-in-one auditing toolkit for identifying common security issues in managed Kubernetes environments. Currently supports Amazon EKS.

Go 322 19 Updated Jan 3, 2024

Tool for building Kubernetes attack paths

Go 802 46 Updated Dec 20, 2024

🧰 Multi Tool Kubernetes Pentest Image

Shell 217 16 Updated Aug 26, 2024

Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).

C 79 7 Updated Jan 28, 2024

A penetration toolkit for container environment

Go 76 18 Updated Dec 9, 2024
Python 171 9 Updated Nov 21, 2024