Container & K8s
Docker Bench for Security
Script checking Docker host configuration against best practices.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Hardening Docker hosts in labs and production reviews.
How
Run script on Docker host; remediate WARN/FAIL items.
Why
Teaches secure container host configuration.
Commands & usage
docker run -it --net host --pid host --userns host --cap-add audit_control \
-v /var/lib:/var/lib:ro docker/docker-bench-security
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Container & K8s
kube-hunter
Hunts for security weaknesses in Kubernetes clusters.
kube-bench
Checks Kubernetes against CIS benchmarks.
Trivy
Vulnerability scanner for containers, filesystems, git repos, and more.
amicontained
Container introspection tool — what capabilities/profile do you have?
CDK (Container Depth Kit)
Toolkit for container penetration testing and escape evaluation.