{}escapepod.red
private beta · founding members

Break the cluster.
Own the pipeline

A hands-on offensive lab platform for Docker, Kubernetes, and CI/CD. Real attack chains. Real privileged escapes. Real cluster takeovers.

$ kubectl auth can-i create pods --as=system:anonymous
yes

Learning paths

Three tracks. One mission.

Break out of the box.

Container Escape

Docker.sock exposure, privileged containers, capability abuse, mount escapes, and kernel CVEs. Get to root on the host.

10 boxes~25 hrs

Take the cluster.

Kubernetes Offense

RBAC abuse, etcd exposure, kubelet API attacks, service account theft, admission controller bypass. Cluster-admin or bust.

10 boxes~25 hrs

Poison the pipeline.

CI/CD Compromise

GitHub Actions injection, runner abuse, OIDC trust misconfigs, malicious dependencies, build poisoning. Own everything downstream.

10 boxes~25 hrs

Featured boxes

Sample what's inside.

01

Sockmonkey

docker.sock · privesc · escape

easy
02

Privileged

capabilities · cgroup · host-mount

easy
03

Tiller

helm · rbac · cluster-admin

medium
04

Anonymous

kubelet · exec · node

medium
05

Manifest Destiny

admission-controller · supply-chain

hard
06

Runaway

runc · CVE-2024-21626 · kernel

insane

Pricing

Simple. Honest. Subscription.

Founding member pricing locked for life. No annual surprises.

Free

$0/ forever

Sample three starter boxes. Decide for yourself.

  • 3 introductory boxes
  • Community Discord
  • Public writeups
Most popular

Pro

$39/ per month

Full access to every box, track, and scenario as they ship.

  • All 30+ boxes
  • All 3 learning tracks
  • Multi-stage scenarios
  • Private VPN access
  • Official writeups

Team

$149/ per month

For internal red teams and consulting shops.

  • 5 seats included
  • Team leaderboards
  • SSO + invoicing
  • Priority support