Container and image security testing
We assess the path from commit to running container: the images you build, the dependencies you inherit, the pipeline that ships them and the runtime that executes them. The supply chain is the soft underbelly most security programs leave untested.
The full attack surface — not just what's visible from the outside.
Image & dependency analysis
Triage, not just scanning
Vulnerable OS packages and language dependencies, stale base images, and what is actually reachable versus merely present, triaged by exploitability rather than raw CVE count.
Image hygiene & build
Default root, leftover secrets
Secrets baked into layers, root containers, excessive capabilities, and Dockerfile and multi-stage build flaws.
Supply-chain integrity
Tracking authenticity
Base-image provenance, unpinned and mutable tags, dependency confusion and typosquatting, and SBOM, signing and attestation (cosign/Sigstore).
CI/CD as attack surface
Workers with root privileges
Over-privileged runners, poisoned pipeline execution, injectable build steps, risk from third-party actions and plugins, and OIDC and credential exposure to cloud.
Registry & artifacts
Full access control
Access control, image tampering, and promotion from untrusted to trusted environments.
Runtime & orchestration
A privileged container means host access
Container escape, privileged and host-mounted workloads, missing admission control and Pod Security, and the blast radius once one container is owned.
Established industry frameworks — not proprietary checklists.
Hardening baselines for build and runtime, used as reference rather than the whole assessment.
Provenance and integrity model used to locate the weak link from source to deploy.
Container security guidance underpinning coverage.
A structured process from scope to retest — no surprises at delivery.

The questions we hear most often before a contract is signed.
A scanner produces a CVE list. We triage it by reachability and exploitability, then test what a scanner cannot reason about: pipeline privilege, build-step injection, secret exposure and runtime escape. The finding is the path, not the inventory.
This is the offensive view: we attack images, registries, the pipeline and the runtime at a point in time. Cloud testing covers the account control plane and IAM. Continuous pipeline security — scanning and gating inside CI — is our DevSecOps offering, a separate, ongoing retainer.
Docker and Kubernetes across the common CI systems, GitHub Actions, GitLab CI, Azure DevOps and Jenkins, and the major registries. We adapt to your toolchain rather than imposing ours.
Contact us
For any matter, you can reach us using the contact details below or via the contact form.
If you would like to speak with us in person, we invite you to book a meeting using the Microsoft Bookings platform.
Book a meeting in Microsoft Bookings