Boxes
Every box, ranked by pain.
Each box is a fully-isolated environment with a real attack surface. No CTF-style flag-hunting through tar files. You get a vulnerable Docker host, k8s cluster, or pipeline — and you root it.
Sockmonkey
Coming soonA mounted docker.sock is a free shell on the host.
docker.sock · privesc · escape
Privileged
Coming soonWhen --privileged was the only flag they read.
capabilities · cgroup · host-mount
Tiller
Coming soonHelm 2 left the door wide open.
helm · rbac · cluster-admin
Anonymous
Coming soonAnonymous auth on the kubelet API. What could go wrong?
kubelet · exec · node
Manifest Destiny
Coming soonMutating admission webhooks accept the strangest things.
admission-controller · supply-chain
Runaway
Coming soonLeaky file descriptors, runc, and a kernel.
runc · CVE-2024-21626 · kernel
Actions Speak
Coming soonpull_request_target was a mistake.
github-actions · injection · runner
Trust Fall
Coming soonMisconfigured OIDC trust = AWS keys for free.
oidc · aws · trust-policy
22 more boxes incoming
First wave drops with public launch. Founding members get early access.