awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
aquasecurity avatar

aquasecurity/kube-hunter

0
View on GitHub↗
5,064 Stars·610 Forks·Python·Apache-2.0·17 Aufrufe

Kube Hunter

Kube-hunter ist ein Sicherheitsscanner und Schwachstellen-Jäger für Kubernetes-Cluster. Es arbeitet als Cloud-natives Penetrationstool, das entwickelt wurde, um Sicherheitsschwachstellen, Fehlkonfigurationen der Infrastruktur und ausnutzbare Lücken durch die Simulation von Angreifertechniken zu identifizieren.

Das Tool zeichnet sich durch eine Dual-Mode-Scan-Engine aus, die sowohl externe Remote-Probes als auch interne Netzwerk-Scans ausführt. Es verfügt über identitätsbasierte Identitätswechsel, die es ermöglichen, Service-Account-Token und Pod-Identitäten zu verwenden, um Sicherheitszugriffe von spezifischen Cluster-Rollen zu simulieren und den potenziellen Explosionsradius einer Container-Kompromittierung zu bestimmen.

Das Projekt deckt ein breites Spektrum an Sicherheitsbewertungsfunktionen ab, einschließlich Cluster-Schwachstellen-Scanning, Mapping der internen Netzwerktopologie und Compliance-Verifizierung. Es kann offengelegte Geheimnisse erkennen, Infrastruktur-Templates auf Fehlkonfigurationen analysieren und aktive Ausnutzungsversuche durchführen, um zu verifizieren, ob entdeckte Schwachstellen ausnutzbar sind.

Die Anwendung wird als eigenständige ausführbare Datei verpackt, um Laufzeitabhängigkeiten während des Deployments zu entfernen.

Features

  • Kubernetes Vulnerability Hunters - Provides an active probing tool to identify exploitable gaps in Kubernetes nodes and service account permissions.
  • Penetration Testing Frameworks - Simulates attacker techniques and pod compromises to identify lateral movement paths and exploitability.
  • Live Cluster Security Scanners - Inspects running Kubernetes clusters to identify security weaknesses and best practice violations.
  • Internal Network Penetration Testers - Analyzes network interfaces from within the environment to identify internal exposure and lateral movement paths.

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI
  • Cloud Native Penetration Testing - Provides a specialized utility for simulating pod compromises and mapping internal network topology in Kubernetes.
  • Exploitability Verification - Verifies if discovered vulnerabilities are actually leverageable by performing active exploitation attempts.
  • Internal Network Discoverers - Maps the network topology of a cluster to identify internal services and unauthorized exposure.
  • Automated Node Discovery - Provides automated discovery of cluster nodes via system APIs to target them for security scanning.
  • Compromise Simulations - Simulates pod compromises as a local unit to determine the potential blast radius and accessible resources.
  • Infrastructure Security Scanners - Analyzes cluster state and infrastructure templates to detect security gaps and non-compliant settings.
  • Kubernetes Cluster Assessments - Probes cluster nodes and APIs to discover exposed secrets and infrastructure gaps to harden the environment.
  • Network Vulnerability Scanning - Probes external IPs or domains from an outside machine to simulate the perspective of an external attacker.
  • Account Impersonation - Simulates security access by assuming the identity of specific Kubernetes service accounts and pod roles.
  • Kubernetes Security Assessments - Scans Kubernetes clusters to identify security weaknesses and misconfigurations that could be exploited.
  • Vulnerability Scanning - Scans clusters to identify security weaknesses and infrastructure misconfigurations to help harden the environment.
  • Active Scanning Engines - Implements an active scanning engine that executes both remote probes and internal network scans to identify vulnerabilities.
  • Network Topology Mapping - Generates maps of discovered nodes within specified network ranges to visualize cluster topology.
  • Kubernetes Compliance Monitoring - Analyzes infrastructure templates and cluster states to verify compliance with security standards and policies.
  • Misconfiguration Scanning - Analyzes infrastructure templates and cluster states against security benchmarks to find non-compliant configurations.
  • Secret Scanning - Scans files and images for sensitive information such as passwords or keys accidentally committed to source control.
  • Security Finding Dispatchers - Routes discovered security vulnerabilities through a filtering pipeline to standard output or remote analysis endpoints.
  • Security Module Integrations - Allows the integration of custom modules that subscribe to cluster events to trigger new security checks.
  • Modular Plugin Frameworks - Provides a plugin-based framework where modular hunter classes subscribe to discovery events to perform security checks.
  • Cloud Native Security - Hunts for security weaknesses in Kubernetes clusters.
  • Attacking - Listed in the “Attacking” section of the Awesome K8s Security awesome list.
  • Application Security - Hunts for security weaknesses in Kubernetes clusters.
  • Cloud Security - Scans Kubernetes clusters for security weaknesses.
  • Hunting Tools - Tool for hunting security weaknesses in Kubernetes clusters.
  • Kubernetes Security - Active security scanner for Kubernetes clusters.
  • Security and Compliance - Scans clusters for potential security weaknesses.
  • Vulnerability Scanning - Hunts for security weaknesses within cluster environments.
  • Star-Verlauf

    Star-Verlauf für aquasecurity/kube-hunterStar-Verlauf für aquasecurity/kube-hunter

    Häufig gestellte Fragen

    Was macht aquasecurity/kube-hunter?

    Kube-hunter ist ein Sicherheitsscanner und Schwachstellen-Jäger für Kubernetes-Cluster. Es arbeitet als Cloud-natives Penetrationstool, das entwickelt wurde, um Sicherheitsschwachstellen, Fehlkonfigurationen der Infrastruktur und ausnutzbare Lücken durch die Simulation von Angreifertechniken zu identifizieren.

    Was sind die Hauptfunktionen von aquasecurity/kube-hunter?

    Die Hauptfunktionen von aquasecurity/kube-hunter sind: Kubernetes Vulnerability Hunters, Penetration Testing Frameworks, Live Cluster Security Scanners, Internal Network Penetration Testers, Cloud Native Penetration Testing, Exploitability Verification, Internal Network Discoverers, Automated Node Discovery.

    Welche Open-Source-Alternativen gibt es zu aquasecurity/kube-hunter?

    Open-Source-Alternativen zu aquasecurity/kube-hunter sind unter anderem: armosec/kubescape — Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and… aquasecurity/kube-bench — kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to… deepfence/threatmapper — ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… snyk/cli — The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies,… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container…

    Open-Source-Alternativen zu Kube Hunter

    Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit Kube Hunter.
    • armosec/kubescapeAvatar von armosec

      armosec/kubescape

      11,482Auf GitHub ansehen↗

      Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and container images against industry compliance and security benchmarks. It functions as a suite of security utilities, including a compliance auditor, a misconfiguration scanner, and a container vulnerability scanner. The project differentiates itself through automated remediation and active enforcement. It can automatically patch operating system vulnerabilities in images and fix security errors within manifest files. It also utilizes an admission controller to block the deployment of

      Go
      Auf GitHub ansehen↗11,482
    • aquasecurity/kube-benchAvatar von aquasecurity

      aquasecurity/kube-bench

      8,078Auf GitHub ansehen↗

      kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

      Go
      Auf GitHub ansehen↗8,078
    • deepfence/threatmapperAvatar von deepfence

      deepfence/ThreatMapper

      5,282Auf GitHub ansehen↗

      ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a vulnerability management system and cloud workload telemetry collector designed to monitor workloads and detect security risks across cloud and container environments. The platform distinguishes itself through a network traffic visualizer that uses machine learning to classify communication patterns and a graph-based attack mapping system to identify high-risk paths between vulnerabilities and network dependencies. Its broader capabilities cover cloud infrastructure complianc

      TypeScriptcloud-nativecloudsecuritycnapp
      Auf GitHub ansehen↗5,282
    • projectdiscovery/naabuAvatar von projectdiscovery

      projectdiscovery/naabu

      5,766Auf GitHub ansehen↗

      Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

      Gocdn-exclusionhacktoberfestnmap
      Auf GitHub ansehen↗5,766
    Alle 30 Alternativen zu Kube Hunter anzeigen→