raesene / kind-of-insecureLinks
Deliberately insecure Kubernetes test clusters built using kind
☆12Updated 5 years ago
Alternatives and similar repositories for kind-of-insecure
Users that are interested in kind-of-insecure are comparing it to the libraries listed below
Sorting:
- Kubernetes Pwnage for all☆57Updated 4 years ago
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container☆106Updated 6 years ago
- Kubernetes Easter CTF☆59Updated 5 years ago
- Pentester-focused Docker registry tool to enumerate and pull images☆111Updated 5 years ago
- ☆51Updated 5 years ago
- Dockerfile Security Checker using OPA Rego policies with Conftest☆60Updated 3 years ago
- ☆27Updated 2 months ago
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆103Updated 5 years ago
- A POC for DNS spoofing in kubernetes clusters. Runs with minimum capabilities, on default installations of kuberentes.☆78Updated 5 years ago
- A tool for automatically gathering sensitive information from exposed Jenkins servers☆104Updated 2 years ago
- ☆34Updated 2 months ago
- Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.☆161Updated last year
- PoC for CVE-2018-1002105.☆223Updated 6 years ago
- Some helpful Helm Charts for pentesters☆39Updated 6 years ago
- Testing/collecting some container breakouts☆94Updated 5 years ago
- 🔐 A concurrent, command-line AWS S3 Fuzzer. Written in Go.☆45Updated 7 years ago
- Writeup of CVE-2017-1002101 with sample "exploit"/escape☆35Updated 7 years ago
- A More or less Random Collection of Scripts for security Testing.☆65Updated 3 years ago
- Going Florida on container keyring masks. A tool to demonstrate the ineffectivity containers have on isolating Linux Kernel keyrings.☆43Updated 2 years ago
- A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform☆165Updated 10 months ago
- ☆50Updated 6 years ago
- ☆20Updated 6 years ago
- Serverless Workshop☆16Updated 2 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆76Updated 3 years ago
- Hayat is a script for report and analyze Google Cloud Platform resources.☆80Updated 5 years ago
- Proof of Concept exploit for Kubernetes CVE-2020-8559☆20Updated 4 years ago
- This repo gives an overview of some GCP metadata API attack and defend patterns☆76Updated 5 years ago
- Kubolt utility for scanning public kubernetes clusters☆110Updated 3 weeks ago
- ☆28Updated 4 years ago
- Conference talk slides and code☆11Updated 4 years ago