Kubernetes security assessment CLI: RBAC, pod-escape, and privilege-escalation path analysis. Cloudsplaining for Kubernetes.
☆96Sep 30, 2026Updated this week
Alternatives and similar repositories for kubesplaining
Users that are interested in kubesplaining are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A kubectl plugin that explains WHY a permission is granted in Kubernetes RBAC by showing the exact Role/ClusterRole + Binding chain.☆17Aug 8, 2026Updated last month
- ☆87Mar 30, 2026Updated 6 months ago
- Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, sec…☆255Jul 1, 2026Updated 3 months ago
- Common code for hardening benchmarks☆10Jul 14, 2025Updated last year
- Jet Container Security Framework (JCSF)☆67Feb 13, 2026Updated 7 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A command-line tool to perform Local Health Check Probes inside Container Images (ECS, Docker)☆54Sep 10, 2026Updated 3 weeks ago
- OIDC SSH login for Linux with DPoP — replace static SSH keys with IdP-issued tokens, no gateway☆25Jul 28, 2026Updated 2 months ago
- Pwning AI Code Interpreters for fun and profit - by Phantom Labs☆27Aug 3, 2026Updated 2 months ago
- Detect phantom IAM users, decode leaked AWS Bedrock and Claude Platform API keys, and prevent LLMjacking. CLI + SCPs + SIEM detection rul…☆36Aug 5, 2026Updated last month
- A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE☆121Sep 14, 2026Updated 2 weeks ago
- Turn Claude into your team's teammate — 50 ready-to-install skills for engineering, security, devops, sales, marketing, and more.☆18Apr 28, 2026Updated 5 months ago
- Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministic…☆174Updated this week
- HoneyZure is a honeypot tool specifically designed for Azure environments, fully provisioned through Terraform. It leverages a Log Analyt…☆17Jun 11, 2024Updated 2 years ago
- Post-exploit a compromised etcd, gain persistence and remote shell to nodes.☆93May 7, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094☆14Apr 6, 2024Updated 2 years ago
- AppArmor and Seccomp profiles for K8S images☆25Dec 9, 2025Updated 9 months ago
- A form mailer web service for JavaScript-based websites☆14Sep 21, 2026Updated last week
- Kubernetes KMS Provider Plugin☆18Aug 20, 2025Updated last year
- kubernetes-for-soc aims to fast-track the learning curve for SOC analysts by enabling them to swiftly grasp the essential concepts and kn…☆56Dec 18, 2023Updated 2 years ago
- OCI Image and Layer disk usage utility☆40Updated this week
- Deliberately vulnerable AWS resources for security assessment demos☆33Aug 20, 2022Updated 4 years ago
- Public repository of all things cloud security.☆47Sep 20, 2024Updated 2 years ago
- Pghostile is a tool to automate the exploitation of PostgreSQL® specific vulnerabilities that could lead to privilege escalation. It can …☆12Aug 17, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆115Sep 25, 2026Updated last week
- AWACS for RBAC. Tool for auditing CRUD permissions in Kubernetes' RBAC.☆46May 21, 2024Updated 2 years ago
- Kubernetes has its “ADCS” -- How To Backdoor a Kubernetes in silence and more persistent?☆39Nov 16, 2025Updated 10 months ago
- Simple tool to identify and remediate the use of the AWS EC2 IMDSv1.☆14Aug 12, 2021Updated 5 years ago
- This application was built to help reduce the amount of time it takes to review AWS Lambda code.☆63Nov 11, 2024Updated last year
- Python script to launch burp scans automatically☆32Jul 18, 2021Updated 5 years ago
- A meta-database collecting resources that compile lists of breaches☆22Sep 13, 2026Updated 2 weeks ago
- Used to check Github actions logs for secrets - specifically tj-actions and reviewdog☆23Mar 18, 2025Updated last year
- ☆115Sep 21, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- mattew crawls target websites, extracts hidden attack surface, runs security analysis, fingerprints technology, and generates professiona…☆17Jul 2, 2026Updated 3 months ago
- Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall …☆130Mar 26, 2026Updated 6 months ago
- Stave finds compound attack paths that single-resource scanners miss. AWS security findings from configuration snapshots without any cred…☆45Updated this week
- Caido plugin to send HTTP requests to external CLI security tools with preview, batch execution, and live output☆24Aug 20, 2026Updated last month
- Cardamon is an audit tool for Prometheus that generates insight into unused metrics from Grafana and Prometheus.☆134Aug 19, 2026Updated last month
- PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.☆23Mar 1, 2026Updated 7 months ago
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆24Mar 16, 2026Updated 6 months ago