awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
aquasecurity avatar

aquasecurity/kube-hunter

0
View on GitHub↗
5,064 星标·610 分支·Python·Apache-2.0·14 次浏览

Kube Hunter

Kube-hunter 是一个用于 Kubernetes 集群的安全扫描器和漏洞猎手。它作为一个云原生渗透工具运行,旨在通过模拟攻击者技术来识别安全弱点、基础设施配置错误和可利用的漏洞。

该工具以其双模式扫描引擎而著称,该引擎既执行远程外部探测,也执行内部网络扫描。它具有基于身份的模拟功能,允许它使用服务账户令牌和 Pod 身份来模拟来自特定集群角色的安全访问,并确定容器受损的潜在影响范围。

该项目涵盖了广泛的安全评估能力,包括集群漏洞扫描、内部网络拓扑映射和合规性验证。它可以检测暴露的密钥、分析基础设施模板中的配置错误,并执行主动利用尝试以验证发现的漏洞是否可被利用。

该应用程序被打包为独立的可执行文件,以在部署期间消除运行时依赖。

Features

  • Kubernetes Vulnerability Hunters - Provides an active probing tool to identify exploitable gaps in Kubernetes nodes and service account permissions.
  • Penetration Testing Frameworks - Simulates attacker techniques and pod compromises to identify lateral movement paths and exploitability.
  • Live Cluster Security Scanners - Inspects running Kubernetes clusters to identify security weaknesses and best practice violations.
  • Internal Network Penetration Testers - Analyzes network interfaces from within the environment to identify internal exposure and lateral movement paths.
  • Cloud Native Penetration Testing - Provides a specialized utility for simulating pod compromises and mapping internal network topology in Kubernetes.
  • Exploitability Verification - Verifies if discovered vulnerabilities are actually leverageable by performing active exploitation attempts.
  • Internal Network Discoverers - Maps the network topology of a cluster to identify internal services and unauthorized exposure.
  • Automated Node Discovery - Provides automated discovery of cluster nodes via system APIs to target them for security scanning.
  • Compromise Simulations - Simulates pod compromises as a local unit to determine the potential blast radius and accessible resources.
  • Infrastructure Security Scanners - Analyzes cluster state and infrastructure templates to detect security gaps and non-compliant settings.
  • Kubernetes Cluster Assessments - Probes cluster nodes and APIs to discover exposed secrets and infrastructure gaps to harden the environment.
  • Network Vulnerability Scanning - Probes external IPs or domains from an outside machine to simulate the perspective of an external attacker.
  • Account Impersonation - Simulates security access by assuming the identity of specific Kubernetes service accounts and pod roles.
  • Kubernetes Security Assessments - Scans Kubernetes clusters to identify security weaknesses and misconfigurations that could be exploited.
  • Vulnerability Scanning - Scans clusters to identify security weaknesses and infrastructure misconfigurations to help harden the environment.
  • Active Scanning Engines - Implements an active scanning engine that executes both remote probes and internal network scans to identify vulnerabilities.
  • Network Topology Mapping - Generates maps of discovered nodes within specified network ranges to visualize cluster topology.
  • Kubernetes Compliance Monitoring - Analyzes infrastructure templates and cluster states to verify compliance with security standards and policies.
  • Misconfiguration Scanning - Analyzes infrastructure templates and cluster states against security benchmarks to find non-compliant configurations.
  • Secret Scanning - Scans files and images for sensitive information such as passwords or keys accidentally committed to source control.
  • Security Finding Dispatchers - Routes discovered security vulnerabilities through a filtering pipeline to standard output or remote analysis endpoints.
  • Security Module Integrations - Allows the integration of custom modules that subscribe to cluster events to trigger new security checks.
  • Modular Plugin Frameworks - Provides a plugin-based framework where modular hunter classes subscribe to discovery events to perform security checks.
  • Cloud Native Security - Hunts for security weaknesses in Kubernetes clusters.
  • Attacking - Listed in the “Attacking” section of the Awesome K8s Security awesome list.
  • Application Security - Hunts for security weaknesses in Kubernetes clusters.
  • Cloud Security - Scans Kubernetes clusters for security weaknesses.
  • Hunting Tools - Tool for hunting security weaknesses in Kubernetes clusters.
  • Kubernetes Security - Active security scanner for Kubernetes clusters.
  • Security and Compliance - Scans clusters for potential security weaknesses.
  • Vulnerability Scanning - Hunts for security weaknesses within cluster environments.

Star 历史

aquasecurity/kube-hunter 的 Star 历史图表aquasecurity/kube-hunter 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Kube Hunter 的开源替代方案

相似的开源项目,按与 Kube Hunter 的功能重合度排序。
  • armosec/kubescapearmosec 的头像

    armosec/kubescape

    11,482在 GitHub 上查看↗

    Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and container images against industry compliance and security benchmarks. It functions as a suite of security utilities, including a compliance auditor, a misconfiguration scanner, and a container vulnerability scanner. The project differentiates itself through automated remediation and active enforcement. It can automatically patch operating system vulnerabilities in images and fix security errors within manifest files. It also utilizes an admission controller to block the deployment of

    Go
    在 GitHub 上查看↗11,482
  • aquasecurity/kube-benchaquasecurity 的头像

    aquasecurity/kube-bench

    8,078在 GitHub 上查看↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    Go
    在 GitHub 上查看↗8,078
  • deepfence/threatmapperdeepfence 的头像

    deepfence/ThreatMapper

    5,282在 GitHub 上查看↗

    ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a vulnerability management system and cloud workload telemetry collector designed to monitor workloads and detect security risks across cloud and container environments. The platform distinguishes itself through a network traffic visualizer that uses machine learning to classify communication patterns and a graph-based attack mapping system to identify high-risk paths between vulnerabilities and network dependencies. Its broader capabilities cover cloud infrastructure complianc

    TypeScriptcloud-nativecloudsecuritycnapp
    在 GitHub 上查看↗5,282
  • projectdiscovery/naabuprojectdiscovery 的头像

    projectdiscovery/naabu

    5,766在 GitHub 上查看↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    在 GitHub 上查看↗5,766
查看 Kube Hunter 的所有 30 个替代方案→

常见问题解答

aquasecurity/kube-hunter 是做什么的?

Kube-hunter 是一个用于 Kubernetes 集群的安全扫描器和漏洞猎手。它作为一个云原生渗透工具运行,旨在通过模拟攻击者技术来识别安全弱点、基础设施配置错误和可利用的漏洞。

aquasecurity/kube-hunter 的主要功能有哪些?

aquasecurity/kube-hunter 的主要功能包括:Kubernetes Vulnerability Hunters, Penetration Testing Frameworks, Live Cluster Security Scanners, Internal Network Penetration Testers, Cloud Native Penetration Testing, Exploitability Verification, Internal Network Discoverers, Automated Node Discovery。

aquasecurity/kube-hunter 有哪些开源替代品?

aquasecurity/kube-hunter 的开源替代品包括: armosec/kubescape — Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and… aquasecurity/kube-bench — kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to… deepfence/threatmapper — ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… snyk/cli — The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies,… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container…