kondukto-io / kntrl
kntrl is an eBPF based runtime agent that monitors and prevents anomalous behaviour defined by you on your pipeline. kntrl achieves this by monitoring kernel calls, and denying access as soon as your defined behaviour is detected.
☆59Updated 4 months ago
Alternatives and similar repositories for kntrl:
Users that are interested in kntrl are comparing it to the libraries listed below
- Kubernetes audit logging, when you don't control the control plane☆67Updated this week
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆77Updated 3 weeks ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- Trust Dexter to ensure that all your images are pinned by digest for better security☆29Updated last year
- A tool to create, transform and attest VEX metadata☆126Updated this week
- Scans SBOMs for vulnerabilities with Grype☆79Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Runtime security plug to protect user containers☆65Updated this week
- Software signing just got easier☆15Updated last year
- Response Engine for managing threats in your Kubernetes☆147Updated this week
- A replacement for "kubectl exec" that works over WebSocket connections.☆36Updated 10 months ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated 9 months ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- AI-generated remediations for Falco audit events☆69Updated last year
- ☆92Updated 8 months ago
- Community curated list of System and Network policy templates for the KubeArmor and Cilium☆42Updated 3 months ago
- ☆52Updated this week
- Runtime detection and response for malicious events in Kubernetes workloads☆41Updated 10 months ago
- An SBOM query language and associated utilities☆54Updated last year
- Sneefer is a PoC project showing how to filter out irrelevent vulnerabilities from container image vulnerability scan results. It is base…☆26Updated last year
- Intent driven security automation framework☆25Updated this week
- a tool to audit the istio service mesh☆173Updated 3 years ago
- sigstore the hard way!☆110Updated 8 months ago
- Generative and mutative fuzzer for Kubernetes admission controller chains by automatically parsing the cluster api specification.☆71Updated last year
- ☆25Updated 8 months ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- ☆56Updated 2 years ago
- BadRobot - Operator Security Audit Tool☆218Updated last week
- Integrates Spiffe and Vault to have secretless authentication☆85Updated this week
- etcd-k8s-extract takes in an etcd data directory or db file used in kubernetes, extracts the kubernetes resources and then writes the res…☆34Updated 3 weeks ago