s3cario
A setuid implementation of a subset of user namespaces, providing a way to run unprivileged containers without requiring root privileges.
Secure your cloud infrastructure with advanced network security solutions.
A setuid implementation of a subset of user namespaces, providing a way to run unprivileged containers without requiring root privileges.
Monitors AWS and GCP accounts for policy changes and alerts on insecure configurations, with support for OpenStack and GitHub monitoring.
Exploit that launches a process on the host from within a Docker container run with the --privileged flag by abusing the Linux cgroup v1 “notification on release” feature.
Comprehensive set of security controls for various AWS services to ensure a secure cloud environment.
Anchore Enterprise is a platform that protects and secures software supply chains end-to-end.
An AWS resource policy security checkup tool that identifies public, external account access, intra-org account access, and private resources.
A Python script that lists all main resources of your AWS account, helping you find resources that affect billing and/or security.
An open-source security tool for AWS, Azure, Google Cloud, and Kubernetes security assessments and audits.
An open source cloud security platform for discovering, prioritizing, and remediating risks in the cloud.
AI-Powered Cloud Assistant for building, securing, and operating cloud environments.
A collection of tools to debug and inspect Kubernetes resources and applications, managing eBPF programs execution and mapping kernel primitives to Kubernetes resources.
Cloud security project focusing on discovering and protecting privileged entities in AWS and Azure environments.
An open-sourced framework for managing resources across hundreds of AWS Accounts
A cloud native application protection platform that provides unified visibility, risk assessment, and remediation capabilities across multi-cloud and hybrid environments.
gVisor is an application kernel that provides isolation for running sandboxed containers.
Collection of Kubernetes manifests creating pods with elevated privileges for security testing.
LogRhythm SIEM is a comprehensive security information and event management platform that collects, analyzes, and responds to security events across an organization's IT infrastructure.
Discover and understand the Docker Layer 2 ICC Bug and its implications on inter-container communication.
A setuid implementation of a subset of user namespaces, providing a way to run unprivileged containers without requiring root privileges.
Cloud Custodian (c7n) is a rules engine for managing public cloud accounts and resources with a focus on security, compliance, and cost optimization.