awesome-repositories.com
博客
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
docker avatar

docker/docker-bench-security

0
View on GitHub↗
9,655 星标·1,040 分支·Shell·Apache-2.0·11 次浏览

Docker Bench Security

This project is a security compliance tool and configuration auditor designed to evaluate Docker deployments against industry security benchmarks. It functions as a script-based scanner that identifies misconfigurations and vulnerabilities within both the host operating system and container settings.

The tool specifically implements the Center for Internet Security standards for Docker to verify host and container configurations. It enables a hardening workflow by comparing system states against these standards to identify security gaps and document compliance status.

The audit engine supports modular test filtering to target specific security domains and generates reports in both plain text and JSON formats. These exports allow audit results to be used for human review or integrated into external security monitoring systems.

Features

  • Security Configuration Auditing - Automates the inspection of Docker host and container configurations to identify security gaps and misconfigurations.
  • Security Audit Scripts - Provides a specialized script for auditing Docker deployments against industry security benchmarks.
  • Compliance Verification Tools - Automates the assessment and reporting of Docker deployments against international security and compliance standards.
  • Container Security - Evaluates container environments and host configurations against benchmarks to ensure adherence to security best practices.
  • Container Security Scanners - Scans Docker host settings and container deployments to identify critical security misconfigurations and vulnerabilities.
  • CIS Benchmark Implementations - Implements specific Center for Internet Security (CIS) benchmarks to evaluate Docker host and container configurations.
  • Container Security Hardening - Provides a workflow to identify vulnerabilities and apply security best practices to harden Docker container settings.
  • Security Benchmark Validations - Provides automated verification of system configurations against validated security reference profiles like the CIS benchmarks.
  • Security Audit Engines - Implements a shell-scripted engine to execute a sequence of configuration checks against a security baseline.
  • Customizable Security Checks - Allows for the selection and customization of specific security checks to target particular deployment domains.
  • Compliance & Audit Tools - Generates detailed audit reports in multiple formats to document compliance with security standards.
  • Container-Host Configuration Auditing - Analyzes differences between the host operating system and container runtime to identify potential security gaps.
  • Test Execution Filtering - Allows users to select specific subsets of security checks for execution via command line arguments.
  • Cloud Native Security - Audits Docker containers against CIS benchmarks.
  • Container Management - Audits Docker deployments against security best practices.
  • Container Security - Benchmarking Docker configurations against CIS standards.
  • Infrastructure as Code Analysis - Checks container deployments against security best practices.
  • Cloud and Container Security - Checks container deployments against industry-standard security benchmarks.
  • Cloud Security - Checks Docker containers against CIS security benchmarks.
  • Container Security Tools - Automated script to check for production deployment best practices.
  • Security and Compliance - Security best-practice auditor for Docker.
  • 安全与加固 - Checks for production security best practices.

Star 历史

docker/docker-bench-security 的 Star 历史图表docker/docker-bench-security 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Docker Bench Security 的开源替代方案

相似的开源项目,按与 Docker Bench Security 的功能重合度排序。
  • aquasecurity/trivyaquasecurity 的头像

    aquasecurity/trivy

    36,462在 GitHub 上查看↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    在 GitHub 上查看↗36,462
  • quay/clairquay 的头像

    quay/clair

    11,012在 GitHub 上查看↗

    Clair is a container image vulnerability scanner and security analyzer. It performs static analysis of container images by matching package contents against vulnerability databases to identify security risks across different package formats and architectures. The project functions as both an image indexer and a vulnerability database manager. It processes container layers into intermediate representations to enable fast security lookups and synchronizes security metadata from multiple external sources to maintain a local registry. Capability areas include continuous security monitoring, whic

    Goclaircontainersdocker
    在 GitHub 上查看↗11,012
  • falcosecurity/falcofalcosecurity 的头像

    falcosecurity/falco

    8,670在 GitHub 上查看↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    在 GitHub 上查看↗8,670
  • cdk-team/cdkcdk-team 的头像

    cdk-team/CDK

    4,692在 GitHub 上查看↗

    CDK is a specialized toolset for container security auditing, container escape exploitation, and cloud infrastructure pentesting. It provides a collection of scripts and tools designed to identify and exploit vulnerabilities in container runtimes to break out of isolated environments and execute commands on the underlying host operating system. The project features a dedicated Docker runtime exploit suite for abusing the Docker API, procfs, and cgroups to gain unauthorized host-level access. It includes specific techniques for bypassing isolation via LXCFS, user namespace exploitation, and ho

    Go
    在 GitHub 上查看↗4,692
查看 Docker Bench Security 的所有 30 个替代方案→

常见问题解答

docker/docker-bench-security 是做什么的?

This project is a security compliance tool and configuration auditor designed to evaluate Docker deployments against industry security benchmarks. It functions as a script-based scanner that identifies misconfigurations and vulnerabilities within both the host operating system and container settings.

docker/docker-bench-security 的主要功能有哪些?

docker/docker-bench-security 的主要功能包括:Security Configuration Auditing, Security Audit Scripts, Compliance Verification Tools, Container Security, Container Security Scanners, CIS Benchmark Implementations, Container Security Hardening, Security Benchmark Validations。

docker/docker-bench-security 有哪些开源替代品?

docker/docker-bench-security 的开源替代品包括: aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… quay/clair — Clair is a container image vulnerability scanner and security analyzer. It performs static analysis of container… falcosecurity/falco — Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and… cdk-team/cdk — CDK is a specialized toolset for container security auditing, container escape exploitation, and cloud infrastructure… anchore/grype — Grype is a command-line security scanner designed to identify known vulnerabilities within container images,… aquasecurity/kube-bench — kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to…