Kubernetes Security Toolkit
<p align="center" </p
---
🎯 Overview
Kubernetes security toolkit for RBAC privilege escalation, container escape, admission controller bypass, ETCD exposure, and cloud metadata access.
| Check | Severity | Description | |-------|----------|-------------| | RBAC Privilege Escalation | 🔴 CRITICAL | cluster-admin bindings, role aggregation | | Container Escape | 🔴 CRITICAL | runc/containerd CVEs, privileged pods | | Admission Controller Bypass | 🟠 HIGH | ValidatingAdmissionWebhook misconfig | | ETCD Unauthorized Access | 🔴 CRITICAL | Secrets dump via etcd | | Kubelet Anonymous Auth | 🟠 HIGH | Pod/exec access without auth | | Cloud Metadata Access | 🟠 HIGH | IMDSv2 bypass, IAM escalation | | Service Mesh Misconfig | 🟡 MEDIUM | Istio/Linkerd mTLS bypass | | CSI Driver Vulnerabilities | 🟡 MEDIUM | Volume mounting escapes |
---
🚀 Quick Start
git clone https://github.com/ridhinva/k8s-security-toolkit.git
cd k8s-security-toolkit
pip install requests kubernetes
python3 k8s_security_toolkit.py --target https://k8s-api:6443 --kubeconfig ~/.kube/config---
⚖️ Disclaimer
For authorized security testing only.