Container & K8s
kube-bench
Checks Kubernetes against CIS benchmarks.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Hardening reviews and purple team K8s assessments.
How
Run on nodes/control plane; export findings.
Why
Maps config to known hardening standards.
Commands & usage
kube-bench
kube-bench --json
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Container & K8s
kube-hunter
Hunts for security weaknesses in Kubernetes clusters.
Trivy
Vulnerability scanner for containers, filesystems, git repos, and more.
Docker Bench for Security
Script checking Docker host configuration against best practices.
amicontained
Container introspection tool — what capabilities/profile do you have?
CDK (Container Depth Kit)
Toolkit for container penetration testing and escape evaluation.