hassan@alsallam:~/projects/kuberange$ bat README.md

KubeRange

A Kubernetes attack range with 83+ scenarios mapped to MITRE ATT&CK

Feature-complete2026securitysource: private · ask me
Attack scenarios catalog
Attack scenarios catalog
Kill chain orchestration view
Kill chain orchestration view
MITRE ATT&CK technique heatmap
MITRE ATT&CK technique heatmap
Security posture assessment dashboard
Security posture assessment dashboard
AI analysis hub
AI analysis hub

What it is

KubeRange is a Kubernetes security lab I built for isolated training environments. It runs as a privileged pod inside a throwaway cluster and lets you execute realistic attack techniques, then study and roll back exactly what happened. It is strictly for authorized labs, CTFs, and defensive research, never production.

The whole thing is a single Go binary using client-go to talk to the cluster, with net/http and WebSocket serving a single-page dashboard that includes a live PTY terminal. The design principle is full reversibility: every created, modified, or host-level change is recorded in SQLite so rollback is idempotent and safe to repeat. The attack catalog is organized against the MITRE ATT&CK container matrix and the OWASP Kubernetes Top 10.

Alongside the offensive catalog it carries defensive tooling, which is the part I care about most: zero-trust network-policy synthesis, RBAC remediation, a Trivy-backed scanner, a runtime monitor, and compliance scoring against CIS and NSA/CISA benchmarks.

Features

Stack

GoKubernetesclient-goSQLiteWebSocketMITRE ATT&CK

83+ attack scenarios · ~148,000 lines of Go · 60+ internal packages