Kubernetes security assessment CLI: RBAC, pod-escape, and privilege-escalation path analysis. Cloudsplaining for Kubernetes.
☆85Jul 31, 2026Updated this week
Alternatives and similar repositories for kubesplaining
Users that are interested in kubesplaining are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A kubectl plugin that explains WHY a permission is granted in Kubernetes RBAC by showing the exact Role/ClusterRole + Binding chain.☆16Jul 18, 2026Updated 2 weeks ago
- ☆87Mar 30, 2026Updated 4 months ago
- Tool to check the CloudTrail configuration and the services where trails are sent, to detect potential attacks to CloudTrail logging.☆13May 25, 2024Updated 2 years ago
- Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, sec…☆208Jul 1, 2026Updated last month
- Detect phantom IAM users, decode leaked AWS Bedrock and Claude Platform API keys, and prevent LLMjacking. CLI + SCPs + SIEM detection rul…☆34Jul 15, 2026Updated 2 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE☆117Jul 20, 2026Updated 2 weeks ago
- Common code for hardening benchmarks☆10Jul 14, 2025Updated last year
- Jet Container Security Framework (JCSF)☆67Feb 13, 2026Updated 5 months ago
- Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministic…☆161Updated this week
- A command-line tool to perform Local Health Check Probes inside Container Images (ECS, Docker)☆54Jul 25, 2026Updated last week
- OIDC SSH login for Linux with DPoP — replace static SSH keys with IdP-issued tokens, no gateway☆23Jul 28, 2026Updated last week
- Pwning AI Code Interpreters for fun and profit - by Phantom Labs☆27Updated this week
- mattew crawls target websites, extracts hidden attack surface, runs security analysis, fingerprints technology, and generates professiona…☆16Jul 2, 2026Updated last month
- HoneyZure is a honeypot tool specifically designed for Azure environments, fully provisioned through Terraform. It leverages a Log Analyt…☆17Jun 11, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094☆14Apr 6, 2024Updated 2 years ago
- AppArmor and Seccomp profiles for K8S images☆25Dec 9, 2025Updated 7 months ago
- A form mailer web service for JavaScript-based websites☆14Updated this week
- Kubernetes KMS Provider Plugin☆18Aug 20, 2025Updated 11 months ago
- Caido plugin to send HTTP requests to external CLI security tools with preview, batch execution, and live output☆23Jun 29, 2026Updated last month
- kubernetes-for-soc aims to fast-track the learning curve for SOC analysts by enabling them to swiftly grasp the essential concepts and kn…☆56Dec 18, 2023Updated 2 years ago
- OCI Image and Layer disk usage utility☆40Jul 23, 2026Updated last week
- Stealth hybrid URL mapper☆26May 1, 2026Updated 3 months ago
- Deliberately vulnerable AWS resources for security assessment demos☆33Aug 20, 2022Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- ☆107Jul 22, 2026Updated last week
- Public repository of all things cloud security.☆47Sep 20, 2024Updated last year
- Enumerate Microsoft service access from a refresh token☆24Apr 1, 2026Updated 4 months ago
- Pghostile is a tool to automate the exploitation of PostgreSQL® specific vulnerabilities that could lead to privilege escalation. It can …☆11Aug 17, 2023Updated 2 years ago
- Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall …☆130Mar 26, 2026Updated 4 months ago
- AWACS for RBAC. Tool for auditing CRUD permissions in Kubernetes' RBAC.☆46May 21, 2024Updated 2 years ago
- Kubernetes has its “ADCS” -- How To Backdoor a Kubernetes in silence and more persistent?☆40Nov 16, 2025Updated 8 months ago
- Simple tool to identify and remediate the use of the AWS EC2 IMDSv1.☆14Aug 12, 2021Updated 4 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- This application was built to help reduce the amount of time it takes to review AWS Lambda code.☆63Nov 11, 2024Updated last year
- Python script to launch burp scans automatically☆32Jul 18, 2021Updated 5 years ago
- AWSDoor is a red team automation tool designed to simulate advanced attacker behavior in AWS environments☆36Sep 17, 2025Updated 10 months ago
- wtftp.py is a tool to attack Microsoft Deployment Toolkit (MDT) and Windows Deployment Services (WDS).☆35Jan 22, 2026Updated 6 months ago
- A meta-database collecting resources that compile lists of breaches☆22Oct 30, 2025Updated 9 months ago
- Used to check Github actions logs for secrets - specifically tj-actions and reviewdog☆23Mar 18, 2025Updated last year
- Cardamon is a cleanup tool for Prometheus that collects unused metrics from Grafana and Prometheus and generates drop statements for them…☆124Updated this week