On this page
Overview
kube-hunter is a Kubernetes security scanner that explores cluster attack surface from different vantage points. It can probe remotely, from node interfaces, or from inside a Pod, then report reachable services and known weaknesses.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Explore a cluster from external, node, and Pod vantage points
Remote, interface, CIDR, and Pod modes let teams compare what an external attacker, a node-local process, or a compromised workload could see.
Sources: [1]
Check discovered services for known weaknesses
The tool discovers Kubernetes-related ports and services, runs registered hunter and vulnerability checks, and associates findings with vulnerability IDs and ATT&CK-style mappings.
Sources: [1]
Separate passive scanning from state-changing active hunting
Normal scanning is designed not to modify cluster state. State-changing tests are only enabled when --active is explicitly requested.
Sources: [1]
Best fit
Fits attack-surface review of existing clusters
It can be useful for inventorying exposed services, reproducing historical Kubernetes security assessments, or seeing what is reachable after a hypothetical Pod compromise.
Sources: [1]
Before adoption
v0.6.8 is the latest release and active development has stopped
The latest release is v0.6.8 from May 18, 2022, and the README states that the project is no longer under active development. Aqua Security recommends Trivy for current Kubernetes misconfiguration and vulnerability scanning.
Do not scan clusters you do not own or have permission to assess
The project documentation explicitly says not to run kube-hunter against a Kubernetes cluster you do not own. Confirm scope and authorization before any remote assessment.
Sources: [1]
Active hunting may change cluster state
The --active mode may perform state-changing operations to explore further. Keep it separate from ordinary scanning and use it only in explicitly authorized test environments after evaluating impact.
Sources: [1]
Official sources
- [1]kube-hunter README(2026-10-03)
- [2]kube-hunter v0.6.8 release(2026-10-03)
- [3]kube-hunter Apache-2.0 license(2026-10-03)
- [4]Trivy(2026-10-03)
Supplemental curator note
The project now explicitly states that it is no longer under active development and Aqua Security recommends Trivy for ongoing Kubernetes scanning. kube-hunter remains useful for reproducing older assessments or understanding its attack-oriented model, but new operational adoption should account for its maintenance status.
Try it in 3 steps
- 1
Install kube-hunter 0.6.8 in a virtual environment
Pin the final release in a Python 3 environment and keep in mind that the project is no longer under active development.
python3 -m venv .venv && . .venv/bin/activate && python -m pip install kube-hunter==0.6.8 - 2
Review the available passive tests
Inspect the test list before scanning. This guide does not enable
--active, which may perform state-changing operations.kube-hunter --list - 3
Passively scan a cluster you own or are authorized to assess
Replace
OWNED_CLUSTER_HOSTonly with a cluster endpoint you own or have explicit permission to assess. Also compare Trivy for new operational deployments.kube-hunter --remote OWNED_CLUSTER_HOST
Growth
Growth trends · Last 30 days
5,087 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 0
- Open PRs
- 8
Development activity is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- vulnerabilities
- kubernetes-clusters
- hacktoberfest
- Stars
- 5,087
- Forks
- 612
- Watchers
- 93
- Open issues
- 74
- Contributors
- 71
- Owner type
- Organization
- Primary language
- Python
- License
- Apache-2.0
- Repository last updated
- Mar 19, 2024
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Falco9,438 Stars
2 shared tag(s) · 2 shared category(s)
detect abnormal Linux, container, and Kubernetes runtime behavior in real time with rule-based kernel event monitoring
C++ - Kyverno8,212 Stars
2 shared tag(s) · 2 shared category(s)
Continuously apply policy as code through Kubernetes admission and background scans
Go - Sherlock93,158 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Check username candidates across more than 400 social networks with an OSINT CLI
Python - JumpServer31,706 Stars
2 shared tag(s) · 1 shared category(s) · Same language
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python - MasterHttpRelayVPN3,935 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Understand it as an experimental HTTP/SOCKS relay stack where a local proxy forwards traffic through services such as Google Apps Script
Python - Cilium25,596 Stars
2 shared tag(s) · 1 shared category(s)
unify Kubernetes networking, security, and observability on an eBPF dataplane
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.