# cdk-team/CDK

📦  Make security testing of K8s, Docker, and Containerd easier.

Repository: https://github.com/cdk-team/CDK
Canonical: https://ross.abutalabs.com/products/cdk
Homepage: https://github.com/cdk-team/CDK/wiki
Language: Go
License: Apache-2.0
License Family: permissive
Topics: penetration, penetration-testing-tools, kubernetes, docker, hacktools, k8s-penetration-toolkit, k8s, linux, exploits, cloud-native, blackhat, hitb, cloud-native-security, container, container-escape, container-security, kernel-exploitation, kubernetes-security, privilege-escalation, vulnerabilities
Last push: 2026-05-01T08:14:30+00:00

## Health v2 (maintenance only)
Score: 70/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 80, release rhythm 40, longevity 100
- inputs: {"age_days": 2127, "days_push": 124, "days_rel": 191, "gap_med": 232.0, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4740, forks 608 (observed 2026-08-28T04:08:57.780079+00:00)

## What it is
CDK is a zero-dependency container penetration toolkit written in Go for security testing of Kubernetes, Docker, and Containerd environments. It bundles environment evaluation, PoCs/EXPs for container escape and privilege escalation, and slim net-tools that work inside minimal containers without OS dependencies.

## Use cases
- evaluate a container for exploitable capabilities and misconfigurations
- escape a privileged or misconfigured container to the host
- take over a Kubernetes cluster from inside a pod
- run exploits in slimmed containers lacking curl, wget, or shell tools
- test container security posture during red team engagements
- deliver a single static binary into a target container for post-exploitation

## When to choose
- you need a single static binary that runs in minimal/slimmed containers with no OS dependencies
- you are doing authorized penetration testing or red teaming of K8s or Docker environments
- you want automated evaluation plus ready-made container escape exploits
- you need built-in net-tools (nc, kcurl, ifconfig, ps) inside a stripped-down container

## When to avoid
- you need defensive monitoring or compliance scanning rather than offensive exploitation
- your targets are non-containerized hosts or traditional VMs
- you lack authorization to test the target systems
- you need a GUI or Windows-native tooling

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, security, vulnerability-scanning, developer-tools
- domain: security, cloud-computing, penetration-testing
- platform: cli
- tags: container-escape, kubernetes-security, docker-security, exploitation, privilege-escalation, red-team, post-exploitation, zero-dependency, containers, devops, linux

## Member repositories
- cdk-team/CDK (main) score 70

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:57.780079+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:18:57.672508+00:00, confidence not recorded.
  - readme: https://github.com/cdk-team/CDK (fetched 2026-08-28T04:08:57.780079+00:00, sha 7a05791c17c1)
  - homepage: https://github.com/cdk-team/CDK/wiki (fetched 2026-08-29T09:02:26.782958+00:00, sha f35dbc87ccd8)
- Data as of 2026-08-30T08:39:29.467469+00:00.
