Container Security
6 tools indexed
Docker and Kubernetes security tools for runtime threat detection, container escape testing, cluster penetration testing, and configuration auditing. These tools assess the security of containerized environments from both offensive and defensive perspectives.
Falco
Cloud-native runtime security. Detects threats in containers, Kubernetes, and Linux hosts using system call monitoring and custom rules.
kube-hunter
Kubernetes penetration testing tool. Hunts for security weaknesses in Kubernetes clusters from inside or outside the network.
CDK
Container escape and exploitation toolkit. Zero-dependency binary for container pentesting with escape exploits and post-exploitation tools.
Deepce
Docker enumeration and privilege escalation. Discover Docker containers, check for misconfigurations, and find escape paths.
Dockle
Container image linter. Checks Docker images for security best practices, CIS benchmarks, and Dockerfile misconfigurations.
Syft
Software Bill of Materials generator. Creates SBOMs from container images and filesystems in SPDX and CycloneDX formats.