calinah / learn-by-hacking-kccn
☆48Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for learn-by-hacking-kccn
- Kubernetes Easter CTF☆58Updated 4 years ago
- Kubernetes Pwnage for all☆54Updated 4 years ago
- Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.☆160Updated last year
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container☆102Updated 5 years ago
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆102Updated 5 years ago
- Pentester-focused Docker registry tool to enumerate and pull images☆104Updated 4 years ago
- ☆233Updated 2 months ago
- Executes commands in a container on a kubelet endpoint that allows anonymous authentication (default)☆113Updated 5 years ago
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆133Updated 4 years ago
- ☆27Updated last week
- This repo gives an overview of some GCP metadata API attack and defend patterns☆76Updated 4 years ago
- Tool for auditing RBACs in Kubernetes☆215Updated 9 months ago
- ☆125Updated 4 months ago
- ☆48Updated 4 years ago
- A POC for DNS spoofing in kubernetes clusters. Runs with minimum capabilities, on default installations of kuberentes.☆74Updated 5 years ago
- Serverless Workshop☆16Updated last year
- Dockerfile Security Checker using OPA Rego policies with Conftest☆59Updated 2 years ago
- Jekyll Files for cloudsecwiki.com☆49Updated 3 years ago
- DEF CON 26 Workshop - Attacking & Auditing Docker Containers Using Open Source☆106Updated 5 years ago
- Kubolt utility for scanning public kubernetes clusters☆109Updated 5 months ago
- ☆28Updated 4 years ago
- PoC for CVE-2018-1002105.☆223Updated 5 years ago
- Burp with Friends☆99Updated last year
- A deliberately vulnerable Kubernetes cluster☆118Updated 11 months ago
- Attacking and Defending Kubernetes Clusters: A Guided Tour☆206Updated 3 years ago
- Deliberately insecure Kubernetes test clusters built using kind☆11Updated 5 years ago
- Scans Slack for API tokens, credentials, passwords, and more using YARA rules☆38Updated 3 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆74Updated 2 years ago
- A beginner-friendly CTF about Kubernetes security.☆76Updated 2 years ago