Enable/disable defenses, then press Simulate pod compromise
Namespace Compromised pod Attack blocked Attack succeeded
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

Kubernetes Cluster Runtime Security

This simulator drops a compromised pod into a running Kubernetes cluster made of namespaces, pods and a host node, and walks it through three real attack steps: lateral movement to a database pod, a privileged API call, and a container escape onto the host. Toggle RBAC, Network Policies and Pod Security independently to see exactly which real Kubernetes defense mechanism stops each step — and what a missing one lets an attacker do next.