cloudflare / sandbox
Simple Linux seccomp rules without writing any code
☆477Updated 6 months ago
Alternatives and similar repositories for sandbox:
Users that are interested in sandbox are comparing it to the libraries listed below
- A language and library for specifying syscall filtering policies.☆312Updated 8 months ago
- User-mode networking for unprivileged network namespaces☆802Updated 2 months ago
- Linux Application Level Firewall based on eBPF and NFQUEUE.☆696Updated last year
- sandboxing and containment tool used in ChromeOS and Android☆305Updated this week
- A dynamic library providing Virtualization-based process isolation capabilities☆1,060Updated last week
- The main libseccomp repository☆837Updated last month
- A general purpose memory allocator that implements an isolation security strategy to mitigate memory safety issues while maintaining good…☆373Updated 9 months ago
- RLBox sandboxing framework☆296Updated last month
- The reliability of disk images, the flexibility of files☆504Updated last week
- An easy way to virtualize the running system☆339Updated last year
- List of resources related to LD_PRELOAD, a mechanism for changing application behavior at run-time☆891Updated 11 months ago
- Dump unix domain socket traffic with bpf☆387Updated last year
- Independent verification of binary packages - Reproducible Builds☆379Updated last month
- Light-weight Dynamic Tracer for Linux☆409Updated 2 months ago
- Dynamic Tracing in Linux☆998Updated 2 months ago
- KernelMemorySanitizer, a detector of uses of uninitialized memory in the Linux kernel☆410Updated 2 weeks ago
- A CNCF Project to Bootstrap & Maintain Trust on the Edge / Cloud and IoT☆461Updated last week
- Go tool for managing Linux filesystem encryption☆924Updated last month
- OCI-interfacing Container runtime for Nabla Containers☆258Updated 3 years ago
- Scripts to slightly improve the security of the Linux boot process with UEFI Secure Boot and TPM support☆275Updated 2 years ago
- This repository contains a tool for generating SELinux security profiles for containers☆517Updated 3 weeks ago
- libeatmydata - because fsync() should be a no-op☆434Updated 11 months ago
- eBPF - extended Berkeley Packet Filter tooling☆123Updated 2 years ago
- OCI hook to trace syscalls and generate a seccomp profile☆319Updated 2 weeks ago
- Framework for running BPF programs with rules on Linux as a daemon. Container aware.☆478Updated 3 years ago
- Linux kernel - See Landlock issues☆40Updated 2 weeks ago
- BSD socket API on steroids☆297Updated 6 months ago
- Turn IP sockets into Unix domain sockets☆365Updated 9 months ago
- Now moved into `github.com/inspektor-gadget/inspektor-gadget/pkg/gadget-collection/gadgets/traceloop`. Tracing system calls in cgroups u…☆198Updated 2 years ago
- eBPF verifier based on abstract interpretation☆411Updated this week