quarkslab / minik8s-ctfLinks
A beginner-friendly CTF about Kubernetes security.
☆78Updated 2 years ago
Alternatives and similar repositories for minik8s-ctf
Users that are interested in minik8s-ctf are comparing it to the libraries listed below
Sorting:
- Kubernetes Pwnage for all☆57Updated 4 years ago
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.☆50Updated 3 years ago
- Kubernetes Easter CTF☆59Updated 5 years ago
- ☆27Updated 2 months ago
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container☆106Updated 6 years ago
- Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass☆17Updated 4 years ago
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆78Updated 4 years ago
- ☆28Updated 4 years ago
- ☆127Updated last year
- Pentester-focused Docker registry tool to enumerate and pull images☆111Updated 5 years ago
- Kubernetes Unhinged Shell 😎☆46Updated 2 years ago
- Ed is a tool used to identify and exploit accessible UNIX Domain Sockets☆27Updated 6 years ago
- A collection of scripts, and tips and tricks for hacking k8s clusters and containers.☆135Updated 8 months ago
- OAuth 2.0 Dynamic Security Scanner☆33Updated 4 years ago
- Collection of Slides From My Conference Talks☆20Updated 2 years ago
- DEbian Cve REproducer Tool☆25Updated 3 weeks ago
- DEF CON 26 Workshop - Attacking & Auditing Docker Containers Using Open Source☆108Updated 5 years ago
- Going Florida on container keyring masks. A tool to demonstrate the ineffectivity containers have on isolating Linux Kernel keyrings.☆43Updated 2 years ago
- Scan your EC2 instance to find its vulnerabilities using Vuls (https://vuls.io/en/)☆89Updated 2 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Updated 3 years ago
- Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.☆161Updated last year
- ☆29Updated 4 years ago
- Tool to automate takeover of DigitalOcean Kubernetes cluster. Check out the blog post for more info.☆16Updated 6 years ago
- Command line fuzzer and bruteforcer 🌪 wfuzz for command☆86Updated 2 years ago
- ☆36Updated 5 years ago
- A repository of previous info-sec presentations I've presented.☆161Updated 8 months ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆14Updated 3 years ago
- HTTP Desync Attack☆28Updated 5 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆49Updated 2 years ago
- This repo gives an overview of some GCP metadata API attack and defend patterns☆76Updated 5 years ago