Showing 28 of 64 projects
A container introspection tool that detects the container runtime and enumerates available security features.
A rootkit that leverages eBPF to implement offensive security techniques like container breakouts, network scanning, and RASP bypass.
A collection of GitHub Actions for Snyk to check projects for vulnerabilities across multiple languages and tools.
A deployment checklist for securely deploying Docker containers on Linux-based hosts.
A security-hardened container runtime for AI coding agents using Incus system containers with real-time threat detection and credential isolation.
A forensic tool for exploring offline Docker filesystems to analyze compromised containers.
A forensic tool for exploring offline Docker container filesystems and metadata from disk images.
An InSpec compliance profile that automates security testing for Docker daemon and containers against CIS benchmarks.
A kubectl plugin for security risk analysis of Kubernetes resources like pods, deployments, daemonsets, and statefulsets.
A curated list of resources for detecting threats and defending Kubernetes systems.
A security inspection tool for managed Kubernetes clusters that identifies common misconfigurations via Docker container and web UI.
An OCI hook that traces container syscalls using eBPF to generate tailored seccomp security profiles.
Tools for vulnerability scanning and compliance auditing of Docker containers and images using OpenSCAP.
A Kubernetes operator that creates checkpoint snapshots of running pods for offline forensic analysis after security incidents.
A fast, lightweight Dockerfile linter written in Go that detects issues, enforces best practices, and provides quality scores.
A Docker-based honeypot that creates disposable containers to capture and analyze attack attempts.
A curated list of awesome projects, tools, articles, and resources related to the Cilium eBPF-based networking and security platform.
A security proxy that protects Docker daemon sockets by filtering API endpoint calls with configurable rules.
A Dockerized SSH bastion that proxies SSH connections to arbitrary containers within a cluster via a single exposed port.
A flexible Docker security audit tool using customizable audit profiles based on CIS benchmarks.
A GitHub Action that scans Docker images for OS and library vulnerabilities in CI/CD pipelines.
A tool that anchors Dockerfile dependencies by replacing image tags with digests and package versions with specific versions for reproducible builds.
A curated collection of resources for container building and runtime security.
A lightweight Nim-based tool to execute programs as a different user, designed for Docker environments as a robust alternative to su-exec and gosu.
A GitHub Action that runs hadolint to analyze Dockerfiles and report violations on pull requests.
Scans Alpine Linux Docker images for Common Vulnerabilities and Exposures (CVEs) using multi-stage builds.
A tool to modify or create OS users with custom IDs in Alpine and BusyBox based Docker images, overcoming hard-coded user limitations.
A Docker build security tool that restricts outbound network access to only allowed domains, preventing supply chain attacks.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.