antitree / keyctl-unmask
Going Florida on container keyring masks. A tool to demonstrate the ineffectivity containers have on isolating Linux Kernel keyrings.
☆43Updated last year
Related projects ⓘ
Alternatives and complementary repositories for keyctl-unmask
- egrets monitors egress☆45Updated 4 years ago
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container☆103Updated 5 years ago
- K8s API Honeypot with Active Defense Capabilities☆39Updated 10 months ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆74Updated 2 years ago
- Kubernetes Easter CTF☆58Updated 4 years ago
- Kubernetes Unhinged Shell 😎☆45Updated 2 years ago
- ☆29Updated 3 years ago
- Pentester-focused Docker registry tool to enumerate and pull images☆104Updated 4 years ago
- ☆27Updated last week
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.☆49Updated 2 years ago
- The SSH Multiplex Backdoor Tool☆62Updated 5 years ago
- ☆28Updated 4 years ago
- Tool to examine the behaviour of setuid binaries under constrained limits.☆62Updated 3 years ago
- A beginner-friendly CTF about Kubernetes security.☆76Updated 2 years ago
- ☆22Updated 2 years ago
- Dockerfile Security Checker using OPA Rego policies with Conftest☆59Updated 2 years ago
- Provide a shell like interface by utilizing osquery's distributed API☆80Updated 4 years ago
- Whitelisting LD_PRELOAD libraries using LD_AUDIT☆61Updated 3 years ago
- Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass☆18Updated 3 years ago
- Docker Secure Computing Profile Generator☆47Updated 3 years ago
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆102Updated 5 years ago
- Kubernetes Pwnage for all☆54Updated 4 years ago
- Testing/collecting some container breakouts☆93Updated 5 years ago
- 🔐 A concurrent, command-line AWS S3 Fuzzer. Written in Go.☆44Updated 7 years ago
- Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.☆160Updated last year
- Serverless honeytoken 🕵🏻♂️☆79Updated last year