dynatrace-oss / koney
Koney is a Kubernetes operator that enables you to define so-called deception policies for your cluster. Koney automates the setup, rotation, and teardown of honeytokens and fake API endpoints, and uses eBPF to detect, log, and forward alerts when your traps have been accessed.
☆33Updated 3 weeks ago
Alternatives and similar repositories for koney
Users that are interested in koney are comparing it to the libraries listed below
Sorting:
- Response Engine for managing threats in your Kubernetes☆159Updated 2 weeks ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆84Updated 4 months ago
- KBOM - Kubernetes Bill of Materials☆315Updated last month
- ☆21Updated 6 months ago
- Threat-informed defense for cloudnative: Reference Implementation of a so-called Honeycluster - for kind (and GKE, RKE2, AKS)☆44Updated this week
- Threat Modeling (based on STRIDE approach) for Kubernetes systems.☆21Updated 7 months ago
- Runtime detection and response for malicious events in Kubernetes workloads☆45Updated last year
- Falco rule repository☆124Updated this week
- Generate a variety of suspect actions that are detected by Falco rulesets☆105Updated 2 months ago
- Kubernetes tool for scanning clusters for network policies and identifying unprotected workloads.☆438Updated 3 weeks ago
- Kubernetes Stranger Danger☆62Updated last year
- Kubernetes audit logging, when you don't control the control plane☆77Updated last week
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆125Updated this week
- This repository contains the container image scanning tool ORCA☆36Updated this week
- KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and files…☆39Updated 7 months ago
- ☆96Updated 3 months ago
- AWACS for RBAC. Tool for auditing CRUD permissions in Kubernetes' RBAC.☆46Updated 11 months ago
- 🧰 Multi Tool Kubernetes Pentest Image☆230Updated last month
- A replacement for "kubectl exec" that works over WebSocket connections.☆38Updated last year
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆81Updated last year
- A simple mitmproxy blueprint to intercept HTTPS traffic from app running on Kubernetes☆67Updated last month
- ☆72Updated this week
- The Falco Project Community☆55Updated last month
- Documentation for the Welkin project - a Kubernetes-based platform for software critical to society☆131Updated this week
- https://github.com/aquasecurity/trivy-operator☆38Updated 2 years ago
- Damn Vulnerable Kubernetes App (DVKA) is a series of apps deployed on Kubernetes that are damn vulnerable.☆138Updated last month
- VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities☆102Updated 7 months ago
- The Kubernetes Security Profiles Operator☆757Updated this week
- Artifact Ratification Framework (CNCF Sandbox)☆262Updated this week