snyk / leaky-vessels-static-detector
Static detection tool for runc and Docker "Leaky Vessels" vulnerabilities
☆96Updated 9 months ago
Alternatives and similar repositories for leaky-vessels-static-detector
Users that are interested in leaky-vessels-static-detector are comparing it to the libraries listed below
Sorting:
- Leaky Vessels Dynamic Detector☆102Updated last month
- Generative and mutative fuzzer for Kubernetes admission controller chains by automatically parsing the cluster api specification.☆74Updated last year
- Runtime detection and response for malicious events in Kubernetes workloads☆45Updated last year
- in-toto is a framework to secure the software supply chain.☆70Updated 4 months ago
- Demo repository for running eBPF in GitHub Actions☆18Updated last month
- A simple mitmproxy blueprint to intercept HTTPS traffic from app running on Kubernetes☆67Updated last month
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.☆36Updated last year
- Making containers more secure with eBPF and Linux Security Modules (LSM)☆228Updated 11 months ago
- Compare data from multiple vulnerability scanners to get a more complete picture of potential exposures.☆64Updated last year
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆84Updated 4 months ago
- agent for handling seccomp descriptors for container runtimes☆46Updated last year
- A replacement for "kubectl exec" that works over WebSocket connections.☆38Updated last year
- Kubernetes offensive framework built in eBPF☆37Updated 2 years ago
- Runtime security plug to protect user containers☆65Updated 2 weeks ago
- ☆74Updated this week
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆54Updated 3 months ago
- Advent of code in eBPF☆47Updated last year
- A convenience tool to generate and store certificates for Hubble Relay mTLS☆26Updated this week
- ☆25Updated this week
- Validate the isolation posture of your container environment.☆277Updated this week
- Falco rule repository☆124Updated this week
- ☆29Updated last week
- 🐝 Ransomware Detection using Machine Learning with eBPF for Linux.☆61Updated 5 months ago
- Threat-informed defense for cloudnative: Reference Implementation of a so-called Honeycluster - for kind (and GKE, RKE2, AKS)☆44Updated this week
- Kubernetes (k8s) admission controller webhook based on Casbin☆35Updated last year
- Kernel-based Process Monitoring on Linux Endpoints for File System, TCP and UDP Networking Events and optionally DNS, HTTP and SYSLOG App…☆63Updated last month
- ✨🔐 CNCF Fuzzers☆123Updated 3 months ago
- An open-source collection of API key rotation tutorials.☆71Updated last month
- Trivy's misconfiguration scanning engine☆218Updated 3 months ago
- ☆72Updated this week