awesome-cloud-native-security
awesome resources about cloud native security 🐿
https://github.com/Metarget/awesome-cloud-native-security
Last synced: 3 days ago
JSON representation
-
0 General
- OWASP Cloud-Native Application Security Top 10
- Hacking and Hardening Kubernetes Clusters by Example (KubeCon 2017)
- 2018绿盟科技容器安全技术报告 (2018-11)
- 2020绿盟科技云原生安全技术报告 (2021-01)
- A Measurement Study on Linux Container Security: Attacks and Countermeasures (ACSAC 2018)
- Kubernetes Security: Operating Kubernetes Clusters and Applications Safely (Book, 2018-09-28)
- Container Security: Fundamental Technology Concepts that Protect Containerized Applications (Book, 2020-04-01)
- MITRE ATT&CK framework for container runtime security with Falco. (2019-05-10)
- Threat matrix for Kubernetes (Microsoft, 2020-04-02)
- Microsoft's Kubernetes Threat Matrix: Here's What's Missing (2020-10-26)
- 国内首个云上容器ATT&CK攻防矩阵发布,阿里云助力企业容器化安全落地 (2020-06-18)
- MITRE ATT&CK Containers Matrix (2021-04-29)
- 最佳实践:发布国内首个K8S ATT&CK攻防矩阵 (青藤, 2021-08-25)
- 2021西部云安全峰会召开:“云安全优才计划”发布,腾讯云安全攻防矩阵亮相 (2021-09-26)
- 云原生安全:基于容器ATT&CK矩阵模拟攻防对抗的思考 (2021-11-01)
- Containers' Security: Issues, Challenges, and Road Ahead (IEEE Access 2019)
- CNCF Cloud Native Security Whitepaper (2021-02-17)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- 컨테이너에서 버그 찾기 어디까지 해봤니 (How to Find Container Platform Bug, CodeEngn 2021)
- Kubernetes Hardening Guidance (by NSA & CISA, 2021-08-03)
- Security Challenges in the Container Cloud (IEEE TPS-ISA 2021)
- 2021西部云安全峰会召开:“云安全优才计划”发布,腾讯云安全攻防矩阵亮相 (2021-09-26)
- 2021西部云安全峰会召开:“云安全优才计划”发布,腾讯云安全攻防矩阵亮相 (2021-09-26)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- Kubernetes Security Checklist and Requirements
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- Secure containerized environments with updated threat matrix for Kubernetes (2021-03-23)
- Threat matrix for Kubernetes (Microsoft, 2020-04-02)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- 最佳实践:发布国内首个K8S ATT&CK攻防矩阵 (青藤, 2021-08-25)
- 2021西部云安全峰会召开:“云安全优才计划”发布,腾讯云安全攻防矩阵亮相 (2021-09-26)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- 《云原生安全:攻防实践与体系构建》
- 2020绿盟科技云原生安全技术报告 (2021-01)
- 最佳实践:发布国内首个K8S ATT&CK攻防矩阵 (青藤, 2021-08-25)
- 2021西部云安全峰会召开:“云安全优才计划”发布,腾讯云安全攻防矩阵亮相 (2021-09-26)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- 最佳实践:发布国内首个K8S ATT&CK攻防矩阵 (青藤, 2021-08-25)
- 2021西部云安全峰会召开:“云安全优才计划”发布,腾讯云安全攻防矩阵亮相 (2021-09-26)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- 最佳实践:发布国内首个K8S ATT&CK攻防矩阵 (青藤, 2021-08-25)
- 2021西部云安全峰会召开:“云安全优才计划”发布,腾讯云安全攻防矩阵亮相 (2021-09-26)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- 最佳实践:发布国内首个K8S ATT&CK攻防矩阵 (青藤, 2021-08-25)
- 2021西部云安全峰会召开:“云安全优才计划”发布,腾讯云安全攻防矩阵亮相 (2021-09-26)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- 最佳实践:发布国内首个K8S ATT&CK攻防矩阵 (青藤, 2021-08-25)
- 2021西部云安全峰会召开:“云安全优才计划”发布,腾讯云安全攻防矩阵亮相 (2021-09-26)
- 企业应用容器化的攻与防 (JINQI-CON 2019)
- Metarget:云原生攻防靶场开源啦! (2021-05-10)
- MITRE ATT&CK framework for container runtime security with Falco. (2019-05-10)
-
1 Offensive
-
1.1 General
- Container Security: Examining Potential Threats to the Container Environment (2019-05-14)
- 云原生环境渗透工具考察 (2020-06-22)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 靶机实验:综合场景下的渗透实战
- Exploit Symlink for Fun and Profit: from Native to Cloud Native (2021-12-08)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
- 红蓝对抗中的云原生漏洞挖掘及利用实录 (2021-03-02)
-
1.2 Kubernetes
- Walls Within Walls: What if your attacker knows parkour? (KubeCon 2019)
- Walls Within Walls: What if Your Attacker Knows Parkour? (Video)
- k0otkit:针对K8s集群的通用后渗透控制技术 (CIS 2020)
- k0otkit: Hack K8s in a K8s Way (Paper)
- k0otkit: Hack K8s in a K8s Way (Video)
- Advanced Persistence Threats: The Future of Kubernetes Attacks (RSA 2020)
- Advanced Persistence Threats: The Future of Kubernetes Attacks (Video)
- Compromising Kubernetes Cluster by Exploiting RBAC Permissions (RSA 2020)
- Compromising Kubernetes Cluster by Exploiting RBAC Permissions (Video)
- Kubernetes Privilege Escalation: Excessive Permissions in Popular Platforms
- Kubernetes Privilege Escalation: Container Escape == Cluster Admin? (Video)
- Kubernetes Privilege Escalation: Container Escape == Cluster Admin? (PPT)
- Command and KubeCTL: Real-world Kubernetes Security for Pentesters (Shmoocon 2020)
- Using Kubelet Client to Attack the Kubernetes Cluster (2020-08-19)
- Attacking Kubernetes Clusters Through Your Network Plumbing: Part 1 (2020-11-05)
- Attacking Kubernetes Clusters Through Your Network Plumbing: Part 2 (2021-05-17)
- Metadata service MITM allows root privilege escalation (EKS / GKE) (2021-02-28)
- etcd未授权访问的风险及修复方案详解 (2021-04-09)
- Creating Malicious Admission Controllers (2021-08-09)
- Don’t let Prometheus Steal your Fire (2021-10-12))
- Metasploit in Kubernetes (2021-11-04)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- Understanding about CVE-2017–1002101 on kubernetes (2018-03-19)
- Fixing the Subpath Volume Vulnerability in Kubernetes (2018-04-04)
- CVE-2017-1002101:突破隔离访问宿主机文件系统
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- Exploiting path traversal in kubectl cp (CVE-2018-1002100, 2018-05-04)
- Disclosing a directory traversal vulnerability in Kubernetes copy – CVE-2019-1002101 (2019-03-28)
- CVE-2019-11246: Clean links handling in cp's tar code (2019-04-30)
- CVE-2019-11249: Incomplete fixes for CVE-2019-1002101 and CVE-2019-11246, kubectl cp potential directory traversal (2019-08-05)
- CVE-2019-11251: kubectl cp symlink vulnerability (2020-02-03)
- The Story of the First Kubernetes Critical CVE (CVE-2018-1002105, 2018-12-04)
- CVE-2018-1002105(k8s特权提升)原理与利用分析报告 (2018-12-08)
- CVE-2018-1002103:远程代码执行与虚拟机逃逸
- Kubernetes hostPort allow services traffic interception when using kubeproxy IPVS (CVE-2019-9946, 2019-03-28)
- Non-Root Containers, Kubernetes CVE-2019-11245 and Why You Should Care, (2019-08-28)
- When it’s not only about a Kubernetes CVE... (CVE-2020-8555, 2020-06-03)
- Kubernetes Vulnerability Puts Clusters at Risk of Takeover (CVE-2020-8558, 2020-07-27)
- Kubernetes man in the middle using LoadBalancer or ExternalIPs (CVE-2020-8554, 2020-12-08)
- Protecting Against an Unfixed Kubernetes Man-in-the-Middle Vulnerability (CVE-2020-8554, 2020-12-21)
- Host MITM attack via IPv6 rogue router advertisements (K8S CVE-2020-10749 / Docker CVE-2020-13401 / LXD / WSL2 / …) (2021-02-28)
- Exploiting and detecting CVE-2021-25735: Kubernetes validating admission webhook bypass (2021-04-28)
- Detecting and Mitigating CVE-2021-25737: EndpointSlice validation enables host network hijack (2021-05-24)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 谁动了我的core\_pattern?CVE-2022-0811容器逃逸漏洞分析
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- ExP: CVE-2017-1002101 by bgeesaman
- ExP: CVE-2021-25735 by darryk10
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- New Attacks on Kubernetes via Misconfigured Argo Workflows (2021-07-20)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- k0otkit:针对K8s集群的通用后渗透控制技术 (CIS 2020)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- Deep Dive into Real-World Kubernetes Threats (2020-02-12)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- Github Repo for k0otkit
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- Kubernetes hostPort allow services traffic interception when using kubeproxy IPVS (CVE-2019-9946, 2019-03-28)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- The Story of the First Kubernetes Critical CVE (CVE-2018-1002105, 2018-12-04)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- Attack Cloud Native Kubernetes (HITB 2021)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- The Story of the First Kubernetes Critical CVE (CVE-2018-1002105, 2018-12-04)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
- Detecting and Mitigating CVE-2021-25737: EndpointSlice validation enables host network hijack (2021-05-24)
- 浅谈云上攻防——CVE-2020-8562漏洞为k8s带来的安全挑战 (2021-10-25)
- 【技术推荐】云原生之Kubernetes安全 (2021-12-18)
- 逃逸风云再起:从CVE-2017-1002101到CVE-2021-25741 (2021-10-12)
-
Sub Categories
Keywords
kubernetes
8
security
7
containers
4
container-security
4
cloud-native
3
kubernetes-security
3
penetration-testing-tools
2
vulnerabilities
2
docker
2
cloud-native-security
2
agent
1
rasp
1
linux-security
1
hids
1
edr
1
cwpp
1
rbac
1
conjbot
1
authorization
1
openshift
1
penetration
1
kube-bench
1
cis-security
1
cis-kubernetes-benchmark
1
cis-benchmark
1
privilege-escalation
1
runtime-security
1
checklist
1
devsecops
1
falco
1
ebpf
1
requirments
1
cncf-project
1
cncf
1
kubelet
1
hacktools
1
exploits
1
container-escape
1
container
1
hitb
1
blackhat
1
tool
1
pentest
1
image-security
1
k8s
1
containerd
1
k8s-penetration-toolkit
1
cloud-security
1
kernel-exploitation
1
kubernetes-clusters
1