Note
Note: The CSF Client is under active development and is getting converted into GoLang for better performace and architecture
From: https://github.com/armourbird/csf
ArmourBird CSF - Container Security Framework is an extensible, modular, API-first framework build for regular security monitoring of docker installations and containers against CIS and other custom security checks.
ArmourBird CSF has a client-server architecture and is thus divided into two components:
a) CSF Client
This component is responsible for monitoring the docker installations, containers, and images on target machines In the initial release, it will be checking against Docker CIS benchmark The checks in the CSF client will be configurable and thus will be expanded in future releases and updates It has been build on top of Docker bench for security
b) CSF Server
This will be the receiver agent for the security logs generated by the various distributed CSF clients (installed on multiple physical/virtual machines) This will also have a UI sub-component for unified management and dashboard-ing of the various vulnerabilities/issues logged by the CSF Clients This server will also expose APIs that can be used for integrating with other systems
Important Note: The tool is currently in beta mode. Hence the debug flag of django (CSF Server) is enabled and the SQLite is used as DB in the same docker container. Hence, spinning up a new docker container will reset the database.