mirror of
https://github.com/aquasecurity/kube-hunter.git
synced 2026-08-20 12:46:25 +00:00
Commit Graph
Select branches
Hide Pull Requests
add-severity
add_plugins_support
add_release_workflow
added_code_analysis_workflow
added_docs_for_exposed_pods
added_security_md
aquadev
bugfix/aws_metadata_scanning
bugfix/cloud_discovery
bugfix/fix_github_actions
bugfix/fix_release_workflow
bugfix/kubernetes_client_error_logs
change_links_to_avd
danielsagi-patch-1
dep/remove-netifaces
dep/remove_netifaces
devops/publish_to_pypi
documentation/mitre
feature/custom_hunting
feature/immersed
feature/mitre_support
feature/multiple_subscription
feature/service-account-token-flag
feature/support_multiple_subscription
fix-certificate-hunting
fix-dns-hunting
fix-hunting-bugs
fix-minor-linting-problem
fix-prettytable
fix/handler_configuration_not_initialized
fix_audit_log_proving
fix_lint_comments
fix_passive_hunting_run_handler
fix_pyinstaller_faliure
fixed-kubelet
improve-dockerfile
improve_aks_hunting
improve_help_message_worker_num_flag
improve_release_workflow
issue-359
lizrice-patch-1
logo
main
owenr-lowercase-severities
refactor/cloud_scanning
refactor_host_discovery
refresh_workflows
remove_cve_scanning
remove_scapy_usage
stop_using_cap_net_raw
update-deps
update-docs-dependencies
update_kramdown_dependency
update_new_aqua_web_design
update_version_on_job_manifest
#1
#10
#100
#101
#104
#105
#106
#11
#114
#115
#116
#117
#119
#12
#121
#123
#125
#128
#129
#13
#130
#131
#132
#133
#134
#135
#136
#137
#139
#14
#140
#141
#142
#145
#146
#147
#15
#150
#153
#154
#156
#157
#158
#159
#160
#161
#162
#163
#165
#166
#167
#168
#169
#170
#173
#175
#176
#178
#18
#181
#182
#183
#187
#188
#189
#19
#192
#193
#195
#196
#197
#198
#199
#2
#20
#200
#201
#202
#203
#204
#205
#206
#208
#209
#21
#210
#211
#212
#214
#215
#217
#218
#219
#22
#220
#221
#222
#223
#224
#225
#226
#227
#228
#229
#23
#231
#232
#233
#236
#237
#238
#239
#24
#242
#243
#244
#247
#248
#249
#25
#250
#251
#252
#255
#256
#257
#258
#259
#260
#261
#263
#264
#265
#266
#267
#269
#27
#270
#271
#272
#273
#275
#276
#278
#279
#281
#283
#286
#288
#29
#294
#297
#298
#299
#3
#30
#302
#303
#309
#310
#311
#313
#314
#315
#317
#318
#32
#323
#325
#327
#328
#33
#330
#332
#335
#337
#338
#34
#342
#344
#347
#350
#351
#354
#355
#357
#360
#361
#362
#363
#364
#365
#367
#368
#369
#371
#372
#376
#377
#378
#382
#383
#384
#385
#386
#387
#388
#389
#39
#390
#391
#392
#396
#397
#398
#399
#4
#400
#401
#402
#403
#406
#407
#409
#411
#412
#414
#415
#416
#419
#42
#420
#421
#422
#423
#423
#424
#425
#427
#429
#430
#431
#436
#439
#441
#447
#448
#450
#451
#453
#454
#455
#458
#458
#461
#463
#464
#466
#468
#470
#471
#474
#478
#481
#482
#484
#485
#487
#488
#489
#49
#49
#491
#492
#495
#497
#5
#50
#500
#501
#504
#506
#508
#509
#51
#51
#510
#510
#511
#511
#518
#518
#519
#52
#520
#528
#528
#53
#530
#530
#539
#539
#54
#540
#540
#542
#542
#543
#543
#544
#546
#55
#550
#551
#555
#555
#57
#58
#6
#60
#62
#63
#65
#66
#67
#68
#69
#7
#72
#73
#74
#76
#77
#8
#81
#82
#85
#86
#87
#88
#89
#9
#90
#92
#93
#94
#95
#96
#97
v0.2.0
v0.3.0
v0.3.0-rc1
v0.3.1
v0.3.2
v0.4.0
v0.4.1
v0.5.0
v0.5.1
v0.5.2
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
Select branches
Hide Pull Requests
add-severity
add_plugins_support
add_release_workflow
added_code_analysis_workflow
added_docs_for_exposed_pods
added_security_md
aquadev
bugfix/aws_metadata_scanning
bugfix/cloud_discovery
bugfix/fix_github_actions
bugfix/fix_release_workflow
bugfix/kubernetes_client_error_logs
change_links_to_avd
danielsagi-patch-1
dep/remove-netifaces
dep/remove_netifaces
devops/publish_to_pypi
documentation/mitre
feature/custom_hunting
feature/immersed
feature/mitre_support
feature/multiple_subscription
feature/service-account-token-flag
feature/support_multiple_subscription
fix-certificate-hunting
fix-dns-hunting
fix-hunting-bugs
fix-minor-linting-problem
fix-prettytable
fix/handler_configuration_not_initialized
fix_audit_log_proving
fix_lint_comments
fix_passive_hunting_run_handler
fix_pyinstaller_faliure
fixed-kubelet
improve-dockerfile
improve_aks_hunting
improve_help_message_worker_num_flag
improve_release_workflow
issue-359
lizrice-patch-1
logo
main
owenr-lowercase-severities
refactor/cloud_scanning
refactor_host_discovery
refresh_workflows
remove_cve_scanning
remove_scapy_usage
stop_using_cap_net_raw
update-deps
update-docs-dependencies
update_kramdown_dependency
update_new_aqua_web_design
update_version_on_job_manifest
#1
#10
#100
#101
#104
#105
#106
#11
#114
#115
#116
#117
#119
#12
#121
#123
#125
#128
#129
#13
#130
#131
#132
#133
#134
#135
#136
#137
#139
#14
#140
#141
#142
#145
#146
#147
#15
#150
#153
#154
#156
#157
#158
#159
#160
#161
#162
#163
#165
#166
#167
#168
#169
#170
#173
#175
#176
#178
#18
#181
#182
#183
#187
#188
#189
#19
#192
#193
#195
#196
#197
#198
#199
#2
#20
#200
#201
#202
#203
#204
#205
#206
#208
#209
#21
#210
#211
#212
#214
#215
#217
#218
#219
#22
#220
#221
#222
#223
#224
#225
#226
#227
#228
#229
#23
#231
#232
#233
#236
#237
#238
#239
#24
#242
#243
#244
#247
#248
#249
#25
#250
#251
#252
#255
#256
#257
#258
#259
#260
#261
#263
#264
#265
#266
#267
#269
#27
#270
#271
#272
#273
#275
#276
#278
#279
#281
#283
#286
#288
#29
#294
#297
#298
#299
#3
#30
#302
#303
#309
#310
#311
#313
#314
#315
#317
#318
#32
#323
#325
#327
#328
#33
#330
#332
#335
#337
#338
#34
#342
#344
#347
#350
#351
#354
#355
#357
#360
#361
#362
#363
#364
#365
#367
#368
#369
#371
#372
#376
#377
#378
#382
#383
#384
#385
#386
#387
#388
#389
#39
#390
#391
#392
#396
#397
#398
#399
#4
#400
#401
#402
#403
#406
#407
#409
#411
#412
#414
#415
#416
#419
#42
#420
#421
#422
#423
#423
#424
#425
#427
#429
#430
#431
#436
#439
#441
#447
#448
#450
#451
#453
#454
#455
#458
#458
#461
#463
#464
#466
#468
#470
#471
#474
#478
#481
#482
#484
#485
#487
#488
#489
#49
#49
#491
#492
#495
#497
#5
#50
#500
#501
#504
#506
#508
#509
#51
#51
#510
#510
#511
#511
#518
#518
#519
#52
#520
#528
#528
#53
#530
#530
#539
#539
#54
#540
#540
#542
#542
#543
#543
#544
#546
#55
#550
#551
#555
#555
#57
#58
#6
#60
#62
#63
#65
#66
#67
#68
#69
#7
#72
#73
#74
#76
#77
#8
#81
#82
#85
#86
#87
#88
#89
#9
#90
#92
#93
#94
#95
#96
#97
v0.2.0
v0.3.0
v0.3.0-rc1
v0.3.1
v0.3.2
v0.4.0
v0.4.1
v0.5.0
v0.5.1
v0.5.2
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
-
973c2a25a0
changed output results table format, added AzureMetadata vulnerability on discovery
daniel_sagi
2018-06-11 20:02:25 +03:00 -
7e939b4544
finished aks spn hunting
daniel_sagi
2018-06-11 18:44:54 +03:00 -
548ae7e486
changed evidence of priviledged containers, also added casting to str in reporter
daniel_sagi
2018-06-11 18:28:01 +03:00 -
9bb835edd3
added azure spn subscription hunting
daniel_sagi
2018-06-11 18:26:58 +03:00 -
838be65967
Added proves for vulnerabilities, added 'evidence' field for every vulnerability to be filled be provers(mostly ActiveHunters)
daniel_sagi
2018-06-11 18:01:54 +03:00 -
75393da91a
simplified kubelet open handlers hunting and types
daniel_sagi
2018-06-11 14:26:09 +03:00 -
01c4aac105
Active hunting is now available by inheriting from ActiveHunter. the hunter wil subscribe only if the --active flag was set.
daniel_sagi
2018-06-11 12:34:34 +03:00 -
70ea40367b
fixed bug: empty remote option
daniel_sagi
2018-06-10 20:10:26 +03:00 -
a2e37927bd
changed directory tree of all modules and packages, for easing on future implementations and extensions
daniel_sagi
2018-06-10 20:09:09 +03:00 -
1934d21c99
changed metavar on remote flag
daniel_sagi
2018-06-10 19:48:34 +03:00 -
faa7571127
1. Added an --active flag, to allow optional "Proof" result, which will do an active hunting of a found vulnerability 2. Added a --remote flag to specify remote clusters/machines for hunting. 3. Improved a bit of the architecture, (Services)
daniel_sagi
2018-06-10 19:34:07 +03:00 -
36e87807e6
1. completely transferred all event types to their corresponding module 2. started working on results table. 3. *added convention* from now on, every vulnerability/service event, should have a __doc__ that describes them. notice the new get_name(), component, and explain() attributes that needs to be implemented as well.
daniel_sagi
2018-06-10 16:27:37 +03:00 -
4a98d698a1
1. Added --pod flag to option "from pod" hunting. this will hunt the internal subnet of the cluster. 2. Added service account token and certificate handling, when running as a pod, to try and access resources that are "secured" 3. Added anonymous auth vulnerability detection 4. Changed requirements.txt for compatibility
daniel_sagi
2018-06-06 10:07:57 +03:00 -
9e8dfbc34e
added hunting for open debug handlers on the kubelet
daniel_sagi
2018-05-28 19:37:30 +03:00 -
a465c3f2eb
1. Changed order of modules and pacakges in directories. 2. Changed method of hidden stacking of event, to send self as an argument, by inheriting from "Hunter" class. where the publish acts as a proxy to the handler. 3. Added new way of categorizing events, while added an option to subscribe to a father event. if en event gets publish, if its father event is hooked, the hook will be triggered 4. Added a reporter in log/ which listens to parent events, meanwhile Vulnerability and OpenService were added. all logging will be made from reporter from now on
daniel_sagi
2018-05-27 17:45:20 +03:00 -
69dba8f1c7
Merge branch 'KubeHunter2'
daniel_sagi
2018-05-24 16:01:43 +03:00 -
290f87de70
1. added log/ 2. Started adding kubelet scanning. 3. Changed events architecture. All events are inheriting from "Event" class. when instantiating and defining a new event class, attributes other than what is important for that perticular event are not needed. the event handler will be stacking the events, so that each event will have all the attributes of its successors. This proccess is invisible to the developer, but needs to be acknowledged. *note: from now on, all executors needs to set self.event to given arg on init* Example (pseudo):
daniel_sagi
2018-05-24 15:25:43 +03:00 -
672c59f576
Added events/ folder. Added dynamic imports for all modules inside: 'events/', 'discovery/', 'hunting/' (you can now add new files with new implementations, and not worry about imports.) Changed port timeout to be 1.5 seconds, more reliable results. Changed default log level to INFO
daniel_sagi
2018-05-15 15:57:36 +03:00 -
3765196140
Changed events architecture, using class objects for all events Added new subscription method for events, using a "subscribe" decorator. Added an optional predicate function to events, for optional filtering on triggered time. used mainly for OpenPortEvent. Added proper logging and argparse Added cleanup of threads when exiting/finishing
daniel_sagi
2018-05-14 17:13:13 +03:00 -
c735b5df95
Started adding KubeProxy hunting, basic services detection mechanism was added. The idea is discovering sub paths of resources in the api and sending them for hunting.
daniel_sagi
2018-05-13 17:02:39 +03:00 -
beb50d40bc
Added .gitignore file, ignoring .pyc files, Also changed modules structure
daniel_sagi
2018-05-10 19:02:07 +03:00 -
48e1307f1d
Added EventQueue class, to handle events. Events now gets processed asynchronously.
daniel_sagi
2018-05-10 14:15:12 +03:00 -
6acf1beec8
changed function describe_service_type in services, to use a dictionary
daniel_sagi
2018-05-08 10:07:51 +03:00 -
eb6cbc2636
Initial Commit
Shir
2018-05-06 19:51:36 +03:00 -
cd880ec50e
Delete everything of Kube Hunter 1.0
Shir
2018-05-06 19:50:00 +03:00 -
c8c8cd9ebd
Fixed failed tries to scan unimplemented services Added an empty url to dashboard hunter Added chrome binary to automatically be install
daniel_sagi
2018-04-23 20:06:10 +03:00 -
1a91ac63da
initial commit
Yehuda Chikvashvili
2018-03-26 17:25:30 +03:00