OWASP / KubeLight
OWASP Kubernetes security and compliance tool [WIP]
☆104Updated last year
Related projects ⓘ
Alternatives and complementary repositories for KubeLight
- Curating Falco rules with MITRE ATT&CK Matrix☆74Updated 8 months ago
- A deliberately vulnerable Kubernetes cluster☆118Updated 11 months ago
- KubeStalk discovers Kubernetes and related infrastructure based attack surface from a black-box perspective.☆167Updated last year
- ☆168Updated this week
- 🧰 Multi Tool Kubernetes Pentest Image☆215Updated 2 months ago
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆34Updated 2 months ago
- BadRobot - Operator Security Audit Tool☆215Updated this week
- A utility to (re-)import findings and language data into DefectDojo☆42Updated last month
- The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use …☆61Updated 5 months ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆66Updated 11 months ago
- A collection of tools to improve your containerized apps security posture☆131Updated 5 months ago
- OWASP Foundation Web Respository☆79Updated 2 months ago
- Kubernetes audit logging, when you don't control the control plane☆65Updated this week
- A curated list of resources about detecting threats and defending Kubernetes systems.☆364Updated last year
- Discover vulnerabilities and container image misconfiguration in production environments.☆53Updated 2 months ago
- Response Engine for managing threats in your Kubernetes☆132Updated this week
- Curated list of security tools☆61Updated 10 months ago
- A full insecure kubernetes application for testing security tools☆54Updated this week
- workshop about cloud-native security☆72Updated 2 years ago
- Protect against subdomain takeover☆92Updated 6 months ago
- Awesome resources about Security in Kubernetes☆40Updated last year
- kubernetes-for-soc aims to fast-track the learning curve for SOC analysts by enabling them to swiftly grasp the essential concepts and kn…☆51Updated 11 months ago
- ☆42Updated 3 years ago
- Process documentation, non-code deliverables, and miscellaneous artifacts of Kubernetes SIG Security☆170Updated 2 weeks ago
- CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.☆267Updated 2 months ago
- VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities☆101Updated last month
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆30Updated last month
- All-in-one auditing toolkit for identifying common security issues in managed Kubernetes environments. Currently supports Amazon EKS.☆318Updated 10 months ago
- KaiMonkey provides vulnerable infrastructure as code (IaC) to help explore and understand common cloud security threats exposed via IaC.☆96Updated 11 months ago