antitree / keyctl-unmask
Going Florida on container keyring masks. A tool to demonstrate the ineffectivity containers have on isolating Linux Kernel keyrings.
☆43Updated last year
Alternatives and similar repositories for keyctl-unmask
Users that are interested in keyctl-unmask are comparing it to the libraries listed below
Sorting:
- egrets monitors egress☆46Updated 5 years ago
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container☆106Updated 6 years ago
- ☆28Updated 4 years ago
- Kubernetes Unhinged Shell 😎☆45Updated 2 years ago
- ☆27Updated 6 months ago
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.☆50Updated 3 years ago
- Provide a shell like interface by utilizing osquery's distributed API☆81Updated 4 years ago
- The SSH Multiplex Backdoor Tool☆64Updated 5 years ago
- Pentester-focused Docker registry tool to enumerate and pull images☆108Updated 5 years ago
- Docker Secure Computing Profile Generator☆48Updated 3 years ago
- K8s API Honeypot with Active Defense Capabilities☆40Updated last year
- A gitbook for doing a null Bangalore session on linux container security to discuss and teach namespaces, cgroups etc.☆20Updated 8 years ago
- 🔐 A concurrent, command-line AWS S3 Fuzzer. Written in Go.☆45Updated 7 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆76Updated 3 years ago
- Whitelisting LD_PRELOAD libraries using LD_AUDIT☆63Updated 3 years ago
- Tool to automate takeover of DigitalOcean Kubernetes cluster. Check out the blog post for more info.☆16Updated 6 years ago
- ☆29Updated 3 months ago
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆103Updated 5 years ago
- Kubernetes Easter CTF☆58Updated 4 years ago
- Proof of Concept exploit for Kubernetes CVE-2020-8559☆20Updated 4 years ago
- List of metadata service endpoints for different cloud providers for your pentesting needs.☆14Updated 6 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Updated 3 years ago
- Writing a container in a few lines of Go code, as seen at DockerCon 2017 and on O'Reilly Safari☆40Updated 4 years ago
- Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass☆18Updated 4 years ago
- Dockerfile Security Checker using OPA Rego policies with Conftest☆60Updated 2 years ago
- Writeup of CVE-2017-1002101 with sample "exploit"/escape☆35Updated 7 years ago
- Serverless honeytoken 🕵🏻♂️☆79Updated 2 years ago
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆77Updated 4 years ago
- A beginner-friendly CTF about Kubernetes security.☆77Updated 2 years ago
- WebBorer is a directory-enumeration tool written in Go.☆44Updated 2 years ago