kube-bench (CIS) + kube-hunter (active) — authenticated K8s cluster audit
Customer creates a read-only ServiceAccount + RoleBinding, exports the kubeconfig, and shares it via secure transfer.
kube-bench iterates the CIS Kubernetes controls, surfacing failures by section (master / node / etcd / policy).
kube-hunter probes for exposed components: anonymous API access, exposed kubelet, dashboard, etcd, etc.
Findings ranked by CVSS + EPSS + KEV. Compliance mapped to CIS / PCI / SOC2 / ISO27001.
€199
Premium or Enterprise · One-time per scan
280 specialized tests + AI-powered analysis
Start Your ScanSelect this addon when configuring your scan