{"repo":"quarkslab/kdigger","free":true,"listed":false,"github":"https://github.com/quarkslab/kdigger","clone":"git clone https://github.com/quarkslab/kdigger.git","description":"Kubernetes focused container assessment and context discovery tool for penetration testing","language":"Go","stars":485,"topics":["kubernetes","pentest","tool","security","containers"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"kdigger kdigger , short for \"Kubernetes digger\", is a context discovery tool for Kubernetes penetration testing. This tool is a compilation of various plugins called buckets to facilitate pentesting Kubernetes from inside a pod. Here is a demo showing kdigger v1.3.0 in action, using only four buckets. Please note that around twenty plugins exist and you can read more about all the features in the following documentation. Please note that this is not an ultimate pentest tool on Kubernetes. Some plugins perform really simple actions that could be performed manually by calling the mount command or listing all devices present in dev with ls /dev for example. But some others automate scanning processes, such as the admission controller scanner. In the end, this tool aims to humbly speed up the pentesting process. Table of content Installation Via releases Build from source With Nix Via Go Usage Digging Generating Fuzzing Details Updates Usage warning Results warning Why another tool? How is this tool built? Areas for improvement How to experiment with this tool? Buckets Admission API Resources Authorization Capabilities Cgroups CloudMetadata ContainerDetect Devices Environment Mount Node PIDNamespace Processes Runtime Services Syscalls Token UserID UserNamespace Version Contributing License Installation kdigger is available on Linux amd64, arm64 and macOS amd64. Please note that kdigger should be mostly run inside of pods on not on your host machine. Via releases For installation ","default_branch":null,"files":null,"tree":[],"storefront":"/r/quarkslab","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/quarkslab/kdigger/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}