NSA and CISA Kubernetes Security Guidance – A Critical Review
research.nccgroup.com
research.nccgroup.com
No package and hash database?
It's trivial to detect when a script is being downloaded to disk or piped to a shell, btw.
I saw this same group post another thread about this recently.
It is completely open source, you can take the executables and run it yourself, compile it, change it, however you feel like :-)
If you do try it, let us know how it is, happy to get feedback!