kube-hunter
Hunt for security weaknesses and misconfigurations in Kubernetes clusters.
Why consider kube-hunter?
kube-hunter is an open-source Kubernetes penetration testing and vulnerability assessment tool written in Python by Aqua Security. Running inside or outside cluster perimeters, kube-hunter actively scans for exposed kubelet APIs, open etcd endpoints, and container privilege escapes.
Learn kube-hunter by building
Practical setup notes, real use cases, and copy-ready examples in one focused guide.
In this guide2 sections
Overview of kube-hunter
kube-hunter searches for exploitable misconfigurations in running Kubernetes clusters.
Docker Quickstart
docker run -it --rm --net=host aquasec/kube-hunterkube-hunter is licensed under the Apache License Version 2.0.
Related tools
More options with a similar category or technology profile.
boringproxy
Simple, self-hosted reverse proxy and tunnel manager for exposing private web services securely.
OWASP ModSecurity
Open-source Web Application Firewall (WAF) engine providing cross-platform HTTP security inspection.
OpenCTI
Open-source platform for managing cyber threat intelligence knowledge and STIX2 relationships.
Maltrail
Malicious traffic detection system utilizing public blacklists and heuristic traffic behavior analysis.