{"repo":"DataDog/KubeHound","free":true,"listed":false,"github":"https://github.com/DataDog/KubeHound","clone":"git clone https://github.com/DataDog/KubeHound.git","description":"Tool for building Kubernetes attack paths","language":"Go","stars":987,"topics":["adversary-emulation","attack-graph","attack-paths","cloud-native-security","exploit","kubernetes","kubernetes-security","mitre-attack","purple-team","red-team"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"KubeHound A Kubernetes attack graph tool allowing automated calculation of attack paths between assets in a cluster. Quick Start Requirements To run KubeHound, you need a couple dependencies + Docker = 19.03 + Docker Compose V2 Install From Release Download binaries are available for Linux / Windows / Mac OS via the releases page or by running the following (Mac OS/Linux): MacOS Notes If downloading the releases via a browser you must run e.g xattr -d com.apple.quarantine kubehound before running to prevent MacOS blocking execution With homebrew KubeHound is available in homebrew-core and you can simply run kubehound should now be in your path. From source If you wish to build KubeHound from source, you will need to checkout a tag before building KubeHound binary will be output to ./bin/build/kubehound . Run Select a target Kubernetes cluster, either: Using kubectx Using specific kubeconfig file by exporting the env variable: export KUBECONFIG=/your/path/to/.kube/config Then, simply run the kubehound binary: For more advanced use case and configuration, see advanced configuration: all the settings available through the configuration file. common operations: the commands available from the KubeHound binary ( dump / ingest ). common errors: troubleshooting guide. Note: KubeHound can be deployed as a serivce (KHaaS), for more information. Using KubeHound Data To query the KubeHound graph data requires using the Gremlin query language via an API call or dedicated graph query UI. ","default_branch":null,"files":null,"tree":[],"storefront":"/r/DataDog","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/DataDog/KubeHound/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}