Container & Kubernetes Security Testing

From image to cluster — misconfigurations, escape paths, and the attack surface nobody watches.

Why this matters: Containers and Kubernetes are the new infrastructure — and the new attack surface. A single misconfigured RBAC role, one overly permissive pod, or a vulnerable container image is a path from your workload to your cluster to your cloud. We test the entire stack: image, runtime, orchestration, and network.

What we cover

  • Container escape and privilege escalation paths
  • Kubernetes RBAC, service accounts, and pod security standards
  • Network policies, ingress/egress, and service mesh exposure
  • Image vulnerabilities, registry access, and base image risks
  • Secrets management: mounted secrets, environment variables, K8s secrets
  • API server, etcd, and control plane security

How we test

1Cluster enumeration

We map your cluster: namespaces, deployments, RBAC bindings, network policies, and exposed services — the attacker view.

2Escape testing

Container escape paths, hostPath mounts, privileged pods, and kernel-level isolation gaps — tested safely with reversible proof.

3Lateral movement

From a compromised pod to other services, the API server, or cloud credentials — how far can access extend?

4Report & harden

Prioritized findings with Kubernetes-specific fixes, CIS benchmark alignment, and a hardening roadmap; retest included.

What you get

  • Complete cluster attack-surface map
  • Escape paths demonstrated with evidence
  • CIS Kubernetes Benchmark alignment
  • Prioritized hardening roadmap

The engagement at a glance

📞 Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote — no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

🔁 Retest included

A verification pass over everything you fix — included in the price, not an add-on.

See the full engagement process → and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

Which platforms do you test?

Kubernetes (EKS, AKS, GKE, self-managed), Docker, and containerd-based platforms. The methodology adapts to your orchestrator.

Do you need access to our cluster?

Read access to the cluster (kubectl with view permissions) plus a test namespace is usually enough. We can also work from outside — testing the exposed attack surface first, then moving inward.

Is container escape testing safe for production?

We use safe, reversible techniques with agreed rules of engagement. Escape paths are proven without causing disruption; emergency stop contact always available.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement — the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation — a researcher replies.

Start the conversation →