OSS Tanbou

probe Kubernetes clusters from outside or inside to expose reachable services and known security weaknesses

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
5,087
Primary language
Python
License
Apache-2.0
Repository last updated
Mar 19, 2024
On this page

Overview

kube-hunter is a Kubernetes security scanner that explores cluster attack surface from different vantage points. It can probe remotely, from node interfaces, or from inside a Pod, then report reachable services and known weaknesses.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Explore a cluster from external, node, and Pod vantage points

Remote, interface, CIDR, and Pod modes let teams compare what an external attacker, a node-local process, or a compromised workload could see.

Sources: [1]

Check discovered services for known weaknesses

The tool discovers Kubernetes-related ports and services, runs registered hunter and vulnerability checks, and associates findings with vulnerability IDs and ATT&CK-style mappings.

Sources: [1]

Separate passive scanning from state-changing active hunting

Normal scanning is designed not to modify cluster state. State-changing tests are only enabled when --active is explicitly requested.

Sources: [1]

Best fit

Fits attack-surface review of existing clusters

It can be useful for inventorying exposed services, reproducing historical Kubernetes security assessments, or seeing what is reachable after a hypothetical Pod compromise.

Sources: [1]

Before adoption

v0.6.8 is the latest release and active development has stopped

The latest release is v0.6.8 from May 18, 2022, and the README states that the project is no longer under active development. Aqua Security recommends Trivy for current Kubernetes misconfiguration and vulnerability scanning.

Sources: [1][2]

Do not scan clusters you do not own or have permission to assess

The project documentation explicitly says not to run kube-hunter against a Kubernetes cluster you do not own. Confirm scope and authorization before any remote assessment.

Sources: [1]

Active hunting may change cluster state

The --active mode may perform state-changing operations to explore further. Keep it separate from ordinary scanning and use it only in explicitly authorized test environments after evaluating impact.

Sources: [1]

Official sources

  1. [1]kube-hunter README(2026-10-03)
  2. [2]kube-hunter v0.6.8 release(2026-10-03)
  3. [3]kube-hunter Apache-2.0 license(2026-10-03)
  4. [4]Trivy(2026-10-03)
Supplemental curator note

The project now explicitly states that it is no longer under active development and Aqua Security recommends Trivy for ongoing Kubernetes scanning. kube-hunter remains useful for reproducing older assessments or understanding its attack-oriented model, but new operational adoption should account for its maintenance status.

Try it in 3 steps

  1. 1

    Install kube-hunter 0.6.8 in a virtual environment

    Pin the final release in a Python 3 environment and keep in mind that the project is no longer under active development.

    python3 -m venv .venv && . .venv/bin/activate && python -m pip install kube-hunter==0.6.8
  2. 2

    Review the available passive tests

    Inspect the test list before scanning. This guide does not enable --active, which may perform state-changing operations.

    kube-hunter --list
  3. 3

    Passively scan a cluster you own or are authorized to assess

    Replace OWNED_CLUSTER_HOST only with a cluster endpoint you own or have explicit permission to assess. Also compare Trivy for new operational deployments.

    kube-hunter --remote OWNED_CLUSTER_HOST
Check the official README

Growth

Growth trends · Last 30 days

5,087 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
0
Open PRs
8

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • vulnerabilities
  • kubernetes-clusters
  • hacktoberfest
Stars
5,087
Forks
612
Watchers
93
Open issues
74
Contributors
71
Owner type
Organization
Primary language
Python
License
Apache-2.0
Repository last updated
Mar 19, 2024
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?