Spotter – Universal Kubernetes Security Scanner & Policy Enforcer

By Madhu Akula on 07 Aug 2025 @ Blackhat : Arsenal
πŸ’» Source Code πŸ”— Link
#kubernetes #cloud-workload-protection #container-security #security-development-lifecycle #secure-coding #security-tools #cloud-compliance
Focus Areas: πŸ“¦ Software Supply Chain Security , πŸ” Application Security , ☁️ Cloud Security , βš™οΈ DevSecOps
This tool demo covers following tools where the speaker has contributed or authored
SPOTTER

Abstract

Spotter is a groundbreaking open-source tool or solution designed to secure Kubernetes clusters throughout their lifecycle. Built on the native tooling of Kubernetes by leveraging CEL (Common Expression Language) for policy definitions, we can define unified security scanning across development, CLI, CI/CD, Admission Controllers, deployments, runtime, and continuous monitoring. Its unique approach enables both enforcement and monitoring modes, ensuring that policies can be applied consistently and mapped directly to industry standards such as CIS, MITRE ATT&CK, etc.

Spotter provides extreamly high flexbility across all Kubernetes phases, providing an innovative approach that no other open-source or commercial solution can replicate. It seamlessly bridges security, DevOps, and platform teams, effectively solving the real-world challenges faced by day-to-day operations.