Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Container Security GitHub Repositories
Explore popular GitHub repositories tagged “container-security”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
📦 Make security testing of K8s, Docker, and Containerd easier.
🧵 CLI tool for directly patching container images!
veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集
Metarget is a framework providing automatic constructions of vulnerable infrastructures.
A Blazing fast Security Auditing tool for Kubernetes
opensecurity: open-source security and compliance. See and secure your cloud, containers, code, networks, deployments, devices. Define your rules, get precise checks, fix gaps fast. Streamlined audits. No fluff.
Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.
Kubernetes Security Checklist and Requirements - All in One (authentication, authorization, logging, secrets, configuration, network, workloads, dockerfile)
awesome resources about cloud native security 🐿
Help building an adaptive and fine-grained pod security policy
k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.
🧰 Multi Tool Kubernetes Pentest Image
Inspect certificate authorities in container images
:closed_lock_with_key: Docker Container for Penetration Testing & Security
🏴☠️ Hacking Guides, Demos and Proof-of-Concepts 🥷
Build your own security agents. Open-source framework for agents with live, read-only access to your infrastructure, with no path to widen it. Reasons across AWS, GCP, Azure, Kubernetes, GitHub and GitLab as one system.
OpenShift Guide. Learn about the Red Hat OpenShift Container Platform, Data Science, Code Ready Containers, Podman, Buildah, and Kubernetes.
A collection of tools to improve your containerized apps security posture
A container image that exfiltrates the underlying container runtime to a remote server
Unified CLI for running AI coding agents in isolated containers. Includes built-in local metrics collection, HTTP traffic tracking, and an analytics dashboard to track agent actions.
一个由长亭自研,直观而可扩展的容器安全 SDK
Simplifying Seccomp enforcement in containerized or non-containerized apps
Trivy Operator Dashboard: A comprehensive tool for Trivy Operator. Offers various dashboards and interactive pages where you can browse and inspect Trivy Reports. Built with C#, .NET 10 (backend), Angular 21, and Node.js 24 (frontend).
An open taxonomy and scoring framework for evaluating AI agent sandboxes: 7 defense layers, 7 threat categories, 3 evaluation dimensions, 27 "sandboxes" scored.
GPU-accelerated secret scanner for code, Git history, containers, cloud, browser assets, and CI. 923 detectors, live verification, CUDA, Metal, WGPU.
Curating Falco rules with MITRE ATT&CK Matrix
🔒🐧 Run command in a secure native sandbox (zero deps)
🚀 DevSecOps intro elective — 10 hands-on labs + 2 bonus hardening OWASP Juice Shop: threat modeling (STRIDE/Threagile), signed commits & secret scanning, SBOM/SCA, SAST + DAST, IaC security (Checkov/KICS), container & supply-chain hardening (Trivy, Cosign), runtime detection with Falco, and DefectDojo vuln management.