Container & K8s
Trivy
Vulnerability scanner for containers, filesystems, git repos, and more.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Assessing image CVEs and IaC misconfigs.
How
Scan image or directory; filter by severity; integrate in CI.
Why
Fast, accurate, widely adopted for container security.
Commands & usage
trivy image nginx:latest
trivy fs --severity HIGH,CRITICAL .
trivy k8s --report summary cluster
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Container & K8s
kube-hunter
Hunts for security weaknesses in Kubernetes clusters.
kube-bench
Checks Kubernetes against CIS benchmarks.
Docker Bench for Security
Script checking Docker host configuration against best practices.
amicontained
Container introspection tool — what capabilities/profile do you have?
CDK (Container Depth Kit)
Toolkit for container penetration testing and escape evaluation.