antitree / keyctl-unmaskLinks
Going Florida on container keyring masks. A tool to demonstrate the ineffectivity containers have on isolating Linux Kernel keyrings.
☆44Updated 2 weeks ago
Alternatives and similar repositories for keyctl-unmask
Users that are interested in keyctl-unmask are comparing it to the libraries listed below
Sorting:
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container☆106Updated 6 years ago
- egrets monitors egress☆46Updated 5 years ago
- Kubernetes Unhinged Shell 😎☆46Updated 3 years ago
- ☆27Updated last month
- Pentester-focused Docker registry tool to enumerate and pull images☆112Updated 5 years ago
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.☆50Updated 3 years ago
- Provide a shell like interface by utilizing osquery's distributed API☆81Updated 5 years ago
- K8s API Honeypot with Active Defense Capabilities☆42Updated last year
- Kubernetes Easter CTF☆59Updated 5 years ago
- Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.☆161Updated 2 years ago
- Tool to automate takeover of DigitalOcean Kubernetes cluster. Check out the blog post for more info.☆17Updated 6 years ago
- Docker Secure Computing Profile Generator☆49Updated 4 years ago
- ☆28Updated 5 years ago
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆103Updated 6 years ago
- A beginner-friendly CTF about Kubernetes security.☆80Updated 3 years ago
- ☆29Updated 9 months ago
- Visualize your Terraform files☆34Updated 5 years ago
- Ed is a tool used to identify and exploit accessible UNIX Domain Sockets☆27Updated 6 years ago
- Salesforce Policy Deviation Checker☆30Updated 5 years ago
- Scans every git push to your Github organisations to find unwanted secrets.☆87Updated 6 months ago
- Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass☆17Updated 4 years ago
- Tool to examine the behaviour of setuid binaries under constrained limits.☆61Updated 4 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆78Updated 3 years ago
- Testing/collecting some container breakouts☆94Updated 6 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Updated 3 years ago
- A POC for DNS spoofing in kubernetes clusters. Runs with minimum capabilities, on default installations of kuberentes.☆78Updated 6 years ago
- Security scanning & static analysis tool☆93Updated last year
- UniSBOM is a tool to build a software bill of materials on any platform with a unified data format.☆36Updated 3 years ago
- Dockerfile Security Checker using OPA Rego policies with Conftest☆62Updated 3 years ago
- Linux Process Discovery. C Library, Go bindings, Runtime.☆223Updated 3 years ago