Containers
Container & Kubernetes Security
Clusters are cloud resources. Score them with the rest of the estate.
10ETLabs lists EKS clusters and ECR repositories through your AWS reader role, AKS clusters through Azure Resource Graph, and GKE clusters through Cloud Asset Inventory on your GCP connection. For workload-level checks on any cluster — EKS, AKS, GKE, or self-managed — you connect its Kubernetes API with a read-only service-account token. Public LoadBalancers, privileged or hostNetwork pods, public EKS, AKS, and GKE API endpoints, AKS clusters without RBAC or with local accounts, GKE legacy ABAC and static credentials, and ECR repositories without scan-on-push show up as findings next to VMs and buckets — one queue, not a bolt-on K8s console. All of that is agentless. If you want more, an optional Helm chart adds a runtime sensor (what AI workloads actually do: shells in model servers, instance-metadata access, unexpected egress, miners) and an admission webhook that warns or blocks risky deploys, with a simulate view before you enforce.

Containers
EKS and AKS from your cloud roles, plus any Kubernetes API you connect with a reader token — clusters as cloud resources.
See it work
Every cloud’s findings, one ranked queue
Findings from each provider share one shape, then 10ET Score orders them by exposure and blast radius.
Many clouds · one ranked queue
01Scan each cloud
Posture jobs list each connected provider’s control plane with its reader role or token — AWS deepest, then Azure, GCP, and Kubernetes.
Sample findings using real rule titles. Scores follow the 10ET Score formula.
What you get
Cluster and registry inventory
EKS clusters and ECR repositories from AWS, AKS clusters from Azure, GKE clusters from GCP, and nodes, services, deployments, and pods from any Kubernetes API you connect with a token.
Public API endpoints
Public EKS API endpoints, AKS and GKE API servers with no authorized IP ranges, and public LoadBalancer services are treated as exposure.
Registry gaps
ECR repositories without scan-on-push are flagged. Other registries (ACR, Artifact Registry) are not assessed in this release.
Optional runtime sensor, honestly scoped
A small DaemonSet samples /proc and the Kubernetes API on each node (not eBPF): shells in model-serving containers, IMDS access, egress to deny-listed or unapproved addresses, miners, and privileged or hostPath pods actually running. Metadata only — never file contents, environment values or request bodies. Short-lived activity between samples can be missed.
Admission policy with simulate
An optional ValidatingAdmissionWebhook enforces, warns or audits per policy — privileged, host namespaces, hostPath, root, limits, untrusted registries, :latest, public model servers, GPU namespaces, cluster-admin notebooks. Simulate against the last N days of inventory first. Fails open by default.
In this module
Step 1
Read cluster APIs
The worker lists cluster resources the service-account token can read, plus EKS and ECR through your AWS role.
Step 2
Flag exposure
Public services, privileged pods, public EKS / AKS / GKE endpoints, weak AKS and GKE cluster auth, and ECR scan-on-push gaps become findings.
Step 3
See them with the estate
Open K8s & containers or inventory filtered by category. Container findings are ranked by 10ET Score; cluster hops join attack paths only when the optional sensor observed them (for example a public service → a pod with a shell and IMDS access → node credentials).
In this release
- EKS, AKS, GKE, and connected-cluster inventory
- Optional runtime sensor and admission webhook (Helm), with policy simulate and signed policy bundles
- Public service, privileged pod, EKS / AKS / GKE endpoint, AKS RBAC and local-account, GKE ABAC / static-credential / Shielded Nodes, and ECR scan-on-push checks
- Shared 10ET Score with the rest of 10ETLabs
On the roadmap
- ACR and Artifact Registry posture
- eBPF syscall-level runtime sensor
Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.
More of the platform
Other modules — not a reprint of this page.
AI security
AI workload security
Trace attack paths to models and agents on SageMaker, Bedrock, Azure AI Foundry and Vertex AI — exposed notebooks, public training data, model weights anyone can swap, retrieval sources fed from public buckets, and workload identities with admin rights.
Code security
Agentless code-to-cloud security
Check Terraform, CloudFormation, ARM, and Kubernetes YAML against built-in pattern rules — in the console or on every pull request — then see the same risk classes on live AWS, Azure, GCP, Kubernetes, and other VPS.
CSPM
Cloud Security Posture Management
Misconfiguration and identity-risk checks across AWS, Azure, GCP, Kubernetes, and other VPS — AWS-first, re-checked on every scan you run or schedule.
CWPP
Cloud Workload Protection
Inventory VMs, Lambda functions, and hosts from the control plane, and look inside VM disks with opt-in, agentless DeepScan.
CIEM
Cloud Identity & Access
AWS IAM, Azure Entra ID and GCP service accounts: missing MFA, standing admins, and effective Azure permissions that can reach sensitive data.
Compliance
Cloud Compliance Monitoring
CIS, SOC 2, PCI DSS, HIPAA, ISO 27001, NIST CSF, FedRAMP, GDPR, DPDP, an AI workload baseline, and your own frameworks — mapped to live findings, with signed evidence packs for auditors.
Vulnerabilities
Cloud Vulnerability Management
ECR scan-on-push gaps from the control plane, plus package CVEs from opt-in DeepScan or the optional host sensor, prioritized by blast radius.