cloudflare / sandbox
Simple Linux seccomp rules without writing any code
☆465Updated 3 months ago
Alternatives and similar repositories for sandbox:
Users that are interested in sandbox are comparing it to the libraries listed below
- A language and library for specifying syscall filtering policies.☆305Updated 5 months ago
- User-mode networking for unprivileged network namespaces☆766Updated 8 months ago
- sandboxing and containment tool used in ChromeOS and Android☆281Updated this week
- An easy way to virtualize the running system☆333Updated last year
- The main libseccomp repository☆818Updated 3 weeks ago
- Dynamic Tracing in Linux☆985Updated 4 months ago
- A general purpose memory allocator that implements an isolation security strategy to mitigate memory safety issues while maintaining good…☆368Updated 6 months ago
- Light-weight Dynamic Tracer for Linux☆406Updated 4 months ago
- A dynamic library providing Virtualization-based process isolation capabilities☆982Updated this week
- The reliability of disk images, the flexibility of files☆475Updated last week
- ☆365Updated last week
- RLBox sandboxing framework☆292Updated 5 months ago
- eBPF - extended Berkeley Packet Filter tooling☆122Updated 2 years ago
- List of resources related to LD_PRELOAD, a mechanism for changing application behavior at run-time☆886Updated 8 months ago
- Userspace eBPF VM☆848Updated this week
- Dump unix domain socket traffic with bpf☆374Updated last year
- Go tool for managing Linux filesystem encryption☆906Updated 3 weeks ago
- Linux Kernel Sanitizers, fast bug-detectors for the Linux kernel☆447Updated 6 months ago
- High-level tracing language for Linux eBPF - development moved to https://github.com/iovisor/bpftrace☆248Updated 5 years ago
- The world's worst kernel module☆296Updated 3 years ago
- A tool for gathering and visualizing kernel scheduling traces on Linux machines☆523Updated 7 months ago
- Sandboxing File System☆46Updated 5 years ago
- firectl is a command-line tool to run Firecracker microVMs☆492Updated 3 weeks ago
- A kernelspace syscall interceptor and randomized faulter☆351Updated last month
- HIBA is a system built on top of regular OpenSSH certificate-based authentication that allows to manage flexible authorization of princip…☆374Updated 2 months ago
- Go packages built on go-tpm providing a high-level API for using TPMs☆243Updated this week
- Now moved into `github.com/inspektor-gadget/inspektor-gadget/pkg/gadget-collection/gadgets/traceloop`. Tracing system calls in cgroups u…☆198Updated last year
- ☆616Updated this week
- Generic eBPF runtime☆149Updated 3 years ago
- Unikernel Linux☆184Updated last month