docker-pentesting
Audited by Socket on Jun 16, 2026
4 alerts found:
Securityx2Malwarex2This fragment is unequivocally an offensive container/host compromise and credential exfiltration playbook. It contains explicit instructions for backdoor persistence (SSH/cron), root-level host execution hijacks (core_pattern pipe, cgroup release_agent), Docker daemon/API abuse for privileged host-mount access, and external exfiltration (reverse shells and curl to attacker endpoints). If present within a supply-chain dependency/package, it represents an extreme security threat and should be treated as malicious content, regardless of whether it is ‘documentation’ or executable scripts embedded in the package.
该内容不是安全实现或防御性文档,而是面向攻击的 Docker Registry/镜像层枚举与凭据滥用指南:包含获取并滥用本地与云凭据(含云元数据 token)、枚举私有仓库与镜像层、将层导出落盘并扫描历史敏感文件、以及在获取镜像后进入容器进行进一步探索。若出现在供应链依赖/可执行脚本中,应视为高风险(数据窃取与横向前置)并进行严格审查与隔离。