k8sstormcenter / honeycluster
Threat-informed defense for cloudnative: Reference Implementation of a so-called Honeycluster - for kind (and GKE, RKE2, AKS)
☆23Updated 3 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for honeycluster
- Response Engine for managing threats in your Kubernetes☆132Updated this week
- Kubernetes audit logging, when you don't control the control plane☆65Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆73Updated this week
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆66Updated 11 months ago
- ☆21Updated this week
- A collection of reusable Github Actions workflows.☆119Updated this week
- sigstore the hard way!☆110Updated 6 months ago
- Runtime security plug to protect user containers☆65Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆139Updated this week
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Updated last year
- An SBOM query language and associated utilities☆54Updated 10 months ago
- Trust Dexter to ensure that all your images are pinned by digest for better security☆29Updated last year
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆59Updated 8 months ago
- ☆24Updated 6 months ago
- Sneefer is a PoC project showing how to filter out irrelevent vulnerabilities from container image vulnerability scan results. It is base…☆26Updated last year
- A tool for in-depth analysis of container checkpoints☆101Updated this week
- ☆74Updated 3 months ago
- ☆19Updated 2 months ago
- This projects contains pre-made policies for Kubernetes Validating Admission Policies. This policy library is based on Kubescape controls…☆48Updated last week
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆30Updated last month
- A replacement for "kubectl exec" that works over WebSocket connections.☆35Updated 7 months ago
- kubectl plugin for signing Kubernetes manifest YAML files with sigstore☆79Updated last week
- OSCAL and Kyverno Policy Demo for AWS☆12Updated last year
- Runtime detection and response for malicious events in Kubernetes workloads☆38Updated 8 months ago
- BadRobot - Operator Security Audit Tool☆215Updated last week
- a tool to audit the istio service mesh☆173Updated 3 years ago
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆121Updated this week
- Intent driven security automation framework☆25Updated 2 weeks ago
- A CLI used to work with the Wolfi OSS project☆57Updated this week