01Identification of insecure hostPath mounts and Docker socket exposure
02Detection of dangerous Linux capability assignments
03CVE-2022-0492 style escape detection via cgroup abuse
04Namespace sharing analysis for PID, Network, and IPC
05Automated auditing of privileged container flags
064,121 GitHub stars