awesome-kubernetes-threat-detection
github.com/jatrost/awesome-kubernetes-threat-detection ↗A curated list of resources about detecting threats and defending Kubernetes systems.
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me attacks resources from awesome-kubernetes-threat-detection"
Installation instructions →What's inside
Conferences
Talks and videos
- A Compendium of Container EscapesAttacks
- Advanced Persistence Threats: The Future of Kubernetes AttacksAttacks
- A Guided Tour of Cilium Service MeshNetworking
- A Treasure Map of Hacking (and Defending) KubernetesAttacks
- Bypassing Falco: How to Compromise a Cluster without Tripping the SOCAttacks
- Cilium: Welcome, Vision and UpdatesNetworking
Books
Tools
- anchorePlatforms
"Software Composition Analysis from Code to Cloud: Enables security teams to find every piece of software in cloud native applications. Block and fix security issues in minutes rather than days."
- AppArmorHardening
"AppArmor is a Linux kernel security module that supplements the standard Linux user and group based permissions to confine programs to a limited set of resources. AppArmor can be configured for any application to reduce its potential attack surface and provide greater in-depth defense."
- Aqua SecurityPlatforms
"Unified Cloud Security: Accelerate secure innovation and protect your entire development lifecycle from code to cloud and back."
- botbAttack
- ConMachiAttack
- controlplaneio/simulatorSimulation / Experimentation
Blogs and Articles
- Attacker persistence in Kubernetes using the TokenRequest API: Overview, detection, and preventionAttacks
- Bad Pods: Kubernetes Pod Privilege EscalationAttacks
- Consider All Microservices Vulnerable — And Monitor Their BehaviorDetection
- Container security fundamentals: Exploring containers as processesHardening
- Container security fundamentals part 2: Isolation & namespacesHardening
- CrowdStrike Discovers First-Ever Dero Cryptojacking Campaign Targeting KubernetesDetection
TTPs / Attack Matrices
Showing a sample of 155 resources. View the full list on GitHub →