kubescape / sneefferLinks
Sneefer is a PoC project showing how to filter out irrelevent vulnerabilities from container image vulnerability scan results. It is based on application monitoring using eBPF and Falco base libraries and writes results in Kubernetes CRDs
☆26Updated last year
Alternatives and similar repositories for sneeffer
Users that are interested in sneeffer are comparing it to the libraries listed below
Sorting:
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Updated 2 years ago
- Scans SBOMs for vulnerabilities with Grype☆83Updated last week
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆125Updated this week
- sigstore the hard way!☆115Updated last year
- A replacement for "kubectl exec" that works over WebSocket connections.☆40Updated last year
- Runtime security plug to protect user containers☆65Updated last week
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- A place for policy work group related proposals and prototypes.☆67Updated last month
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆23Updated 7 months ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- Community curated list of System and Network policy templates for the KubeArmor and Cilium☆46Updated 3 months ago
- ☆20Updated last month
- Generate a variety of suspect actions that are detected by Falco rulesets☆106Updated last month
- Administrative tooling for Falco☆108Updated 2 weeks ago
- Kubernetes audit logging, when you don't control the control plane☆82Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- Intent driven security automation framework☆26Updated last month
- Security advisory data for Wolfi☆19Updated last week
- Evolution process of The Falco Project☆53Updated this week
- Response Engine for managing threats in your Kubernetes☆166Updated this week
- BadRobot - Operator Security Audit Tool☆221Updated this week
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆62Updated 3 years ago
- 🔍 Rekor transparency log monitoring and alerting☆27Updated last year
- This repository contains the code used during my demo at BSidesNYC 2023 where I presented a new method for analysing volatile memory in G…☆1Updated 9 months ago
- A standalone exporter for vulnerability reports and other CRs created by Trivy Operator (formerly Starboard).☆63Updated last week
- ☆14Updated 3 months ago
- Trust Dexter to ensure that all your images are pinned by digest for better security☆29Updated last year
- A tool to create, transform and attest VEX metadata☆147Updated 3 weeks ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆98Updated last week
- An admission controller service and kubectl plugin to handle container drift in K8s clusters☆124Updated 3 years ago