Pragmatic Security Leader | Author, Speaker & Trainer @ BlackHat, DEFCON, USENIX, OWASP, SANS, etc. | Securing Cloud Native, Containers, Kubernetes, Infra, Apps
kubernetes-goat. Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground π
5.7khacker-container. The Swiss Army Container for Cloud Native Security. Container with all the list of useful tools/commands while hacking and securing Containers, Kubernetes Clusters, and Cloud Native workloads.
295wincmdfu. Windows one line commands that make life easier, shortcuts and command line fu.
192security-automation-with-ansible-2. Ansible Playbooks for Security Automation with Ansible2 book
104spotter. Spotter is a comprehensive Kubernetes security scanner that uses CEL-based rules to identify security vulnerabilities, misconfigurations, and compliance violations across your Kubernetes clusters, manifests, and CI/CD pipelines.
76docker-security-checker. Dockerfile Security Checker using OPA Rego policies with Conftest
63hacked-emails. Command line hacked-emails
17PaloaltoNetworks-Custom-URL-Category. Automated PAN Firewall Custom URL Category using Python and PAN API
14aws-iam-analyser. AWS IAM Analysis utility to gather entire useful information from an AWS account
10introduction-to-containers-using-docker. An Introduction to Containers using Docker and using it for Security Automation - null Bangalore Puliya
10awesome-devsecops. Curating the best DevSecOps resources and tooling.
8what-is-this-secret. What is this secret?
7attacking-and-auditing-docker-containers-and-kubernetes-clusters. Appsecco training course content on Attacking and Auditing Dockers Containers and Kubernetes Clusters
7defcon-26-workshop-attacking-and-auditing-docker-containers. DEF CON 26 Workshop - Attacking & Auditing Docker Containers Using Open Source
6null-puliya-markdown-automation. Automating Documentation, Presentation, Knowledge base using Markdown (Zero to Hero)
6werdlists. :keyboard: Wordlists, Dictionaries and Other Data Sets for Writing Software Security Test Cases
5DockerSecurityPlayground. A Microservices-based framework for the study of Network Security and Penetration Test techniques
5Docker-OSX. Mac in Docker! Run near native OSX-KVM in Docker! X11 Forwarding!
5k8s-sec.github.io. Links and resources for the O'Reilly Kubernetes Security book
4random-scripts. some useful scripts
4x11docker. Run GUI applications and desktops in docker. Focus on security.
4kubernetes-network-security-boundaries. Python
4madhuakula.com. Madhu Akula's website
4financial-user-group. π°πΈβοΈFor those interested in running Kubernetes in highly regulated environments, particularly financial services
3Kubernetes-DNS-spoofing-POC. Proof-of-Concept python script that implements DNS spoofing attack in Kubernetes environment from a pod located on a Worker server
3madhuakula.
3linux-container-security-docs. A gitbook for doing a null Bangalore session on linux container security to discuss and teach namespaces, cgroups etc.
3Java. All Algorithms implemented in Java
2nullblr-bachaav-aismd. null Bangalore Public Bachaav 10 December 2016 Automated Infrastructure Security Monitoring & Defence
2OSX-KVM. Run macOS on QEMU/KVM. With OpenCore Now! No free support is provided. Open PR(s) to fix problems.
2play-with-docker.github.io. Play with docker class-room repo
1yaql. Yet another query language. Mirror of code maintained at opendev.org.
1vet. Tool to achieve policy driven vetting of open source dependencies
1java-sec-code. Java web common vulnerabilities and security code which is base on springboot and spring security
1cloudquery. cloudquery transforms your cloud infrastructure into SQL database for easy monitoring, governance and security.
1cq-provider-okta. CloudQuery Provider for Okta
1keychaindump. A proof-of-concept tool for reading OS X keychain passwords
1hugoThemesSiteBuilder. The source for https://themes.gohugo.io
1