SELinuxProject / selint
Static code analysis of refpolicy style SELinux policy
☆42Updated last month
Alternatives and similar repositories for selint:
Users that are interested in selint are comparing it to the libraries listed below
- IPE is a Linux Security Module (LSM), which allows for a configurable policy to enforce integrity requirements on the whole system. IPE b…☆61Updated 2 months ago
- LKRG bypass methods☆72Updated 5 years ago
- ☆15Updated 4 years ago
- Linux kernel - See Landlock issues☆40Updated 3 weeks ago
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆116Updated 2 years ago
- ☆26Updated 2 years ago
- unofficial grsecurity gpl release☆22Updated 6 years ago
- A proof-of-concept Linux clone of Santa, Google's binary authorization system for macOS☆30Updated 2 years ago
- ☆22Updated 3 years ago
- (Linux Kernel) Stack Monitoring Tool☆44Updated 3 years ago
- SELinux Policy Analysis Tools☆179Updated 3 months ago
- upstream for seccheck☆15Updated 6 years ago
- CITL's static analysis engine for native code artifacts☆20Updated 3 years ago
- SELinux policy analysis tool☆17Updated 4 years ago
- ☆86Updated 9 months ago
- Coverage-Guided Greybox Distributed Fuzzer☆130Updated this week
- Automated dynamic security analysis by emulation of IoT firmware images in CI-pipelines.☆11Updated 3 years ago
- Checks for tpm vulnerabilities☆37Updated 2 years ago
- ☆20Updated 7 months ago
- MapGuard is a library that enforces a security policy for mmap based page allocations.☆21Updated 3 months ago
- Automate generation of syzkaller's grammar☆15Updated 2 years ago
- Armory Drive - USB encrypted drive with mobile unlock over BLE☆54Updated 2 months ago
- Build custom Docker seccomp profiles for containers by finding syscalls it uses.☆90Updated 4 years ago
- Minimal viable OSS-Fuzz integration☆8Updated last year
- Kernel Address Isolation to have Side-channels Efficiently Removed☆220Updated 3 years ago
- Pulled out Linux kernel code to run in userland so they could be targeted by AFL and KLEE☆20Updated 5 years ago
- A simple, self-contained regression test suite for the Linux Kernel's audit subsystem☆23Updated 7 months ago
- Check linux sources dump for known CVEs.☆129Updated last week
- suidsnoop is a tool based on eBPF LSM programs that logs whenever a suid binary is executed and implements custom allow/deny lists.☆15Updated 3 years ago
- A binary hardening system☆106Updated last year