CLOUDPANICCLOUDPANIC

Container and image security testing

If an attacker owns your pipeline, they don't need to breach production. They ship the breach into it, signed and deployed.

We assess the path from commit to running container: the images you build, the dependencies you inherit, the pipeline that ships them and the runtime that executes them. The supply chain is the soft underbelly most security programs leave untested.

Test scope

The full attack surface — not just what's visible from the outside.

Image & dependency analysis

Triage, not just scanning

Vulnerable OS packages and language dependencies, stale base images, and what is actually reachable versus merely present, triaged by exploitability rather than raw CVE count.

Image hygiene & build

Default root, leftover secrets

Secrets baked into layers, root containers, excessive capabilities, and Dockerfile and multi-stage build flaws.

Supply-chain integrity

Tracking authenticity

Base-image provenance, unpinned and mutable tags, dependency confusion and typosquatting, and SBOM, signing and attestation (cosign/Sigstore).

CI/CD as attack surface

Workers with root privileges

Over-privileged runners, poisoned pipeline execution, injectable build steps, risk from third-party actions and plugins, and OIDC and credential exposure to cloud.

Registry & artifacts

Full access control

Access control, image tampering, and promotion from untrusted to trusted environments.

Runtime & orchestration

A privileged container means host access

Container escape, privileged and host-mounted workloads, missing admission control and Pod Security, and the blast radius once one container is owned.

Built on recognised standards

Established industry frameworks — not proprietary checklists.

methodology.sh
CIS Docker / Kubernetes Benchmarks

Hardening baselines for build and runtime, used as reference rather than the whole assessment.

SLSA supply-chain framework

Provenance and integrity model used to locate the weak link from source to deploy.

NIST SP 800-190

Container security guidance underpinning coverage.

In one container engagement, we traced a CI/CD misconfiguration to full cloud tenant access in a single day. The CVE scanner flagged 240 items. The actual attack path used none of them.
From scope to retest

A structured process from scope to retest — no surprises at delivery.

Diagram of the penetration testing cycle: scope and reconnaissance, testing, reporting
Common questions

The questions we hear most often before a contract is signed.

A scanner produces a CVE list. We triage it by reachability and exploitability, then test what a scanner cannot reason about: pipeline privilege, build-step injection, secret exposure and runtime escape. The finding is the path, not the inventory.

This is the offensive view: we attack images, registries, the pipeline and the runtime at a point in time. Cloud testing covers the account control plane and IAM. Continuous pipeline security — scanning and gating inside CI — is our DevSecOps offering, a separate, ongoing retainer.

Docker and Kubernetes across the common CI systems, GitHub Actions, GitLab CI, Azure DevOps and Jenkins, and the major registries. We adapt to your toolchain rather than imposing ours.

Contact us

For any matter, you can reach us using the contact details below or via the contact form.

Calendar icon for scheduling meetings

If you would like to speak with us in person, we invite you to book a meeting using the Microsoft Bookings platform.

Book a meeting in Microsoft Bookings
E-mail:
Send us an email and our team will get back to you within 1–2 business days.
Phone:
We also offer phone contact from Monday to Friday, 9:00 AM – 5:00 PM.
0 / 5000
The personal data provided will be used solely for the purpose of handling your inquiry or contact request. The data controller is CLOUDPANIC Sp. z o.o. You can find detailed information in our privacy policy.