NationalSecurityAgency / seabeeLinks
Hardens eBPF tools against privileged attackers via policy-based access controls
☆43Updated this week
Alternatives and similar repositories for seabee
Users that are interested in seabee are comparing it to the libraries listed below
Sorting:
- A project to collect eBPF verifier errors and how they can be resolved☆43Updated 8 months ago
- [Experimental] jail for Go modules☆94Updated 3 weeks ago
- Making containers more secure with eBPF and Linux Security Modules (LSM)☆230Updated last year
- agent for handling seccomp descriptors for container runtimes☆47Updated last year
- A tool for in-depth analysis of container checkpoints☆122Updated this week
- OCI hook to trace syscalls and generate a seccomp profile☆335Updated last month
- tool for building and running VMs for development and testing☆105Updated this week
- 🔍 Seccomp profiling and function-level tracing tool.☆163Updated 4 months ago
- Shape your traffic the BPF way☆79Updated 2 years ago
- An query language and interactive tooling to work with SBOM data.☆14Updated last year
- A tool to help programmers debug and analyze Linux Kernel BPF verification failures.☆45Updated this week
- A CLI used to work with the Wolfi OSS project☆67Updated last week
- A replacement for "kubectl exec" that works over WebSocket connections.☆41Updated last year
- sget is a keyless safe script retrieval and execution tool☆18Updated 3 years ago
- A layer 2 switch for VMs powered by eBPF☆43Updated 7 months ago
- eBPF Map Prometheus Exporter☆24Updated 2 months ago
- Go modules related to OCI (Open Container Initiative) registries☆29Updated last month
- [Soft-deprecated] Reproducible apt/dnf/apk/pacman, with content-addressing☆110Updated last year
- COSI Runtime☆50Updated this week
- Security Observation Tool written in Rust inspired by Tetragon☆26Updated last month
- Services for storing and searching information about software content and vulnerabilities☆53Updated last week
- Code-snippets for developing eBPF programs☆16Updated 3 weeks ago
- TC, XDP, KProbe and CGroup eBPF based simple Ethernet interface traffic monitor and reporting tool☆122Updated 2 weeks ago
- go library for processing container images and simulating a squash filesystem☆97Updated last week
- Launch configurable virtual machines with libkrun☆157Updated last week
- Run VM disk images using Podman / Docker / Kubernetes.☆233Updated 3 weeks ago
- Intent driven security automation framework☆26Updated last month
- A Kubernetes CSI plugin to automatically mount SPIFFE certificates to Pods using ephemeral volumes☆82Updated this week
- Kit for building Falco drivers: kernel modules or eBPF probes☆67Updated last week
- suidsnoop is a tool based on eBPF LSM programs that logs whenever a suid binary is executed and implements custom allow/deny lists.☆16Updated 3 years ago