Skip to content
View christophetd's full-sized avatar

Sponsoring

@simonw

Block or report christophetd

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Container security

26 repositories

A container analysis and exploitation tool for pentesters and engineers.

Go 675 57 Updated Sep 27, 2023

Peirates - Kubernetes Penetration Testing tool

Go 1,421 128 Updated Jan 20, 2026

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Go 106 13 Updated Nov 30, 2018

A client for kubelet

Go 871 88 Updated Aug 6, 2025

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492

Shell 48 17 Updated Mar 9, 2022

A container image that exfiltrates the underlying container runtime to a remote server

C 136 11 Updated Oct 10, 2022

Correlates serviceaccounts and pods to the permissions granted to them via rolebindings and clusterrolesbindings.

Python 35 2 Updated May 18, 2022

⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

Go 7,110 666 Updated Mar 12, 2024

Kubernetes focused container assessment and context discovery tool for penetration testing

Go 475 20 Updated Nov 7, 2025

The Kubernetes Security Profiles Operator

C 830 127 Updated Feb 13, 2026

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

HTML 5,410 956 Updated Nov 18, 2025

Writing a container in a few lines of Go code, as seen at DockerCon 2017 and on O'Reilly Safari

Go 1,985 336 Updated Aug 12, 2025

A beginner-friendly CTF about Kubernetes security.

Shell 81 6 Updated Aug 9, 2022

POC for CVE-2022-23648

Dockerfile 36 12 Updated Mar 29, 2022

Review Access - kubectl plugin to show an access matrix for k8s server resources

Go 1,385 59 Updated Apr 5, 2023

Evaluate the RBAC permissions of Kubernetes identities through policies written in Rego

Go 350 39 Updated Mar 21, 2025

Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.

Go 163 16 Updated Nov 28, 2025

Runs checks to see if an EKS cluster follows EKS Best Practices.

Python 937 92 Updated Jan 16, 2026
TypeScript 41 3 Updated Dec 12, 2022

This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures

Shell 12 1 Updated Dec 21, 2022

Show who has RBAC permissions to perform actions on different resources in Kubernetes

Go 902 82 Updated Jul 17, 2024

A tool to scan Kubernetes cluster for risky permissions

Python 1,412 138 Updated May 25, 2025

A collection of manifests that will create pods with elevated privileges.

Shell 676 117 Updated Dec 30, 2025

Kubernetes audit logging, when you don't control the control plane

Go 90 7 Updated Feb 14, 2026

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

Python 645 110 Updated Nov 21, 2019

An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster

Go 470 63 Updated Feb 13, 2026