Spotter – Universal Kubernetes Security Engine

By Madhu Akula on 10 Dec 2025 @ Blackhat : Arsenal
πŸ’» Source Code πŸ”— Link
#kubernetes #container-security #cloud-security-posture-management #security-testing
Focus Areas: πŸ“¦ Software Supply Chain Security , πŸ” Application Security , ☁️ Cloud Security , βš™οΈ DevSecOps
This tool demo covers following tools where the speaker has contributed or authored
SPOTTER

Abstract

Spotter is an open-source Kubernetes security engine designed to secure clusters throughout their entire lifecycle. It uses Kubernetes-native tooling and CEL (Common Expression Language) for policy definitions, enabling unified security scanning across development, CLI, CI/CD, Admission Controllers, deployments, runtime, and continuous monitoring. It provides both enforcement and monitoring modes and maps policies to standards such as CIS and MITRE ATT&CK.

Presented at Black Hat Europe 2025 Arsenal, December 8-11, London.