{"repo":"cyberark/KubiScan","free":true,"listed":false,"github":"https://github.com/cyberark/KubiScan","clone":"git clone https://github.com/cyberark/KubiScan.git","description":"A tool to scan Kubernetes cluster for risky permissions","language":"Python","stars":1429,"topics":["kubernetes","rbac","authorization","conjbot"],"license":"GPL-3.0","category":"deployment-docker-iac","readme_excerpt":"[![GitHub release][release-img]][release] [![License][license-img]][license] A tool for scanning Kubernetes cluster for risky permissions in Kubernetes's Role-based access control (RBAC) authorization model. The tool was published as part of the \"Securing Kubernetes Clusters by Eliminating Risky Permissions\" research https://www.cyberark.com/threat-research-blog/securing-kubernetes-clusters-by-eliminating-risky-permissions/. --- Table of Contents - Overview - What can it do? - Usage - Container - Directly with Python3 - Prerequisites - Example for installation on Ubuntu - With KubeConfig file - From a remote with ServiceAccount token - Examples - Demo - Risky Roles YAML - Showcase - License - References --- Overview KubiScan helps cluster administrators identify permissions that attackers could potentially exploit to compromise the clusters. This can be especially helpful on large environments where there are lots of permissions that can be challenging to track. KubiScan gathers information about risky roles\\clusterroles, rolebindings\\clusterrolebindings, users and pods, automating traditional manual processes and giving administrators the visibility they need to reduce risk. What can it do? - Identify risky Roles\\ClusterRoles - Identify risky RoleBindings\\ClusterRoleBindings - Identify risky Subjects (Users, Groups and ServiceAccounts) - Identify risky Pods\\Containers - Dump tokens from pods (all or by namespace) - Get associated RoleBindings\\ClusterRoleBindings to Role, Clu","default_branch":null,"files":null,"tree":[],"storefront":"/r/cyberark","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cyberark/KubiScan/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}