{"repo":"cdk-team/CDK","free":true,"listed":false,"github":"https://github.com/cdk-team/CDK","clone":"git clone https://github.com/cdk-team/CDK.git","description":"📦 Make security testing of K8s, Docker, and Containerd easier.","language":"Go","stars":4732,"topics":["penetration","penetration-testing-tools","kubernetes","docker","hacktools","k8s-penetration-toolkit","k8s","linux","exploits","cloud-native"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"CDK - Zero Dependency Container Penetration Toolkit English 简体中文 Legal Disclaimer Usage of CDK for attacking targets without prior mutual consent is illegal. CDK is for security testing purposes only. Overview CDK is an open-sourced container penetration toolkit, designed for offering stable exploitation in different slimmed containers without any OS dependency. It comes with useful net-tools and many powerful PoCs/EXPs and helps you to escape container and take over K8s cluster easily. Quick Start Run cdk eva to get evaluate info and a recommend exploit, then run cdk run to start the attack. Installation/Delivery Download latest release in https://github.com/cdk-team/CDK/releases/ Drop executable files into the target container and start testing. TIPS: Deliver CDK into target container in real-world penetration testing If you have an exploit that can upload a file, then you can upload CDK binary directly. If you have a RCE exploit, but the target container has no curl or wget , you can use the following method to deliver CDK: 1. First, host CDK binary on your host with public IP. 2. Inside the victim container execute Usage Features CDK has three modules: 1. Evaluate: gather information inside container to find potential weakness. 2. Exploit: for container escaping, persistance and lateral movement 3. Tool: network-tools and APIs for TCP/HTTP requests, tunnels and K8s cluster management. Evaluate Module Usage Tactics Script Supported Usage/Example --- --- --- --- Information","default_branch":null,"files":null,"tree":[],"storefront":"/r/cdk-team","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cdk-team/CDK/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}