Skip to content
@k8sstormcenter

Kubernetes Storm Center

Free and Open Threat Intelligence for the Cloud Native Ecosystem

Welcome to the Kubernetes Storm Center 👋 Let's take the fear out of threats (by understanding them)

We want to enable (truly) free and open source threat intelligence for the cloud native ecosystem.

Keeping it simple, such that many non-experts can instrument their existing cluster-templates, stream and collect the information of how attackers traverse their "honeycluster", and publish their threat intelligence.

These "honeyclusters" can also be used to pro-actively test perceived or modelled threats on a continuous improvement mindset.

It should be noted, that a large usecase is to "simulate" the attack by using synthetic attacks (attack yourself) to test if a team can a) detect and b) defend and c) incident respond (as required by e.g. NIS-2).

Contributions, ideas and discussions from the cloud-native community are very welcome. We encourage users to report any issues.

There is a SLACK for the community [https://join.slack.com/t/k8sstorm/signup] Community Office Hrs: Every second Friday at 11am CET at ZOOM

This is a not-for-profit community project (with absolutely no liability). Unless specifically specified otherwise, Apache License applies.

MVPTreeLogo Make the attack trees visible !

Glossary

Term Definition Example
Threat Model Entire superset of threats to your org
Threat Model -Branch One threat to your org Initial Access: Application Exploit leads to Priv Esc , Abuse of Service Account leads to Lateral Movement, Persistence is established on worker Node
Attack Model Concrete implementation of Threat Model Branch Exploit Wordpress Version 1.1.1 CVE 1234 allows RCE , POD SA creates PV/C , C2 software planted in PVC
Bait Purpuseful initial access to Threat Model Branch Commit creds to github
Events Individual occurences in the IT system Application logs, Network logs, TracingPolicy logs , Audit logs
TracingPolicy eBPF instruction to hook into kernel Kprobe on filedescriptor "write" access in /tmp
Stix Observables Relevant events that have occured File '/tmp/wanky' has been written
Stix Indicators Attack Model nodes necessary for Attack 'access to /etc/shadow'
Pattern Match between Observable (event) and Indicator '/usr/bin/mycat /etc/shadow' <-> access to sensitive file

Pinned Loading

  1. honeycluster honeycluster Public

    Threat-informed defense for cloudnative: Reference Implementation of a so-called Honeycluster - for kind (and GKE, RKE2, AKS)

    Shell 32 3

Repositories

Showing 6 of 6 repositories
  • honeycluster Public

    Threat-informed defense for cloudnative: Reference Implementation of a so-called Honeycluster - for kind (and GKE, RKE2, AKS)

    k8sstormcenter/honeycluster’s past year of commit activity
    Shell 32 Apache-2.0 3 18 (1 issue needs help) 0 Updated Mar 10, 2025
  • cti-stix-visualization Public

    Fork of the OASIS STIX Visualizer to use as Developer UI for creating Attack Trees

    k8sstormcenter/cti-stix-visualization’s past year of commit activity
    JavaScript 2 BSD-3-Clause 0 8 (2 issues need help) 0 Updated Feb 25, 2025
  • kubescape Public Forked from kubescape/kubescape

    Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

    k8sstormcenter/kubescape’s past year of commit activity
    Go 0 Apache-2.0 867 0 0 Updated Jan 31, 2025
  • .github Public

    Welcome to the Kubernetes Storm Center

    k8sstormcenter/.github’s past year of commit activity
    2 Apache-2.0 0 0 0 Updated Jan 12, 2025
  • threatintel Public archive

    Consume, analyse and create threatintelligence from your honey clusters

    k8sstormcenter/threatintel’s past year of commit activity
    Jupyter Notebook 6 Apache-2.0 0 5 0 Updated Dec 23, 2024
  • KubeHound Public Forked from DataDog/KubeHound

    Tool for building Kubernetes attack paths

    k8sstormcenter/KubeHound’s past year of commit activity
    Go 2 Apache-2.0 51 0 0 Updated Oct 17, 2024

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…