cloudflare / sandboxLinks
Simple Linux seccomp rules without writing any code
☆516Updated 7 months ago
Alternatives and similar repositories for sandbox
Users that are interested in sandbox are comparing it to the libraries listed below
Sorting:
- A language and library for specifying syscall filtering policies.☆344Updated 2 months ago
- sandboxing and containment tool used in ChromeOS and Android☆356Updated this week
- List of resources related to LD_PRELOAD, a mechanism for changing application behavior at run-time☆909Updated last year
- Dump unix domain socket traffic with bpf☆418Updated 2 years ago
- The main libseccomp repository☆897Updated last month
- Linux Application Level Firewall based on eBPF and NFQUEUE.☆706Updated 2 years ago
- An easy way to virtualize the running system☆351Updated 2 years ago
- A general purpose memory allocator that implements an isolation security strategy to mitigate memory safety issues while maintaining good…☆385Updated last month
- libeatmydata - because fsync() should be a no-op☆475Updated last year
- eBPF - extended Berkeley Packet Filter tooling☆133Updated 3 years ago
- User-mode networking for unprivileged network namespaces☆880Updated 8 months ago
- RLBox sandboxing framework☆318Updated last month
- ☆282Updated last year
- Linux kernel - See Landlock issues☆44Updated 2 months ago
- Snuffy is a simple command line tool to inspect SSL/TLS data.☆292Updated 5 years ago
- The reliability of disk images, the flexibility of files☆614Updated 3 weeks ago
- A kernelspace syscall interceptor and randomized faulter☆358Updated last year
- Light-weight Dynamic Tracer for Linux☆427Updated 2 months ago
- Libraries to abstract aspects of working with TPMs for the purposes of attestation☆415Updated 2 weeks ago
- Dynamic Tracing in Linux☆1,026Updated 5 months ago
- Scripts to slightly improve the security of the Linux boot process with UEFI Secure Boot and TPM support☆284Updated 3 years ago
- KernelMemorySanitizer, a detector of uses of uninitialized memory in the Linux kernel☆421Updated 10 months ago
- Sandboxing File System☆46Updated 6 years ago
- BSD socket API on steroids☆323Updated last year
- HIBA is a system built on top of regular OpenSSH certificate-based authentication that allows to manage flexible authorization of princip…☆390Updated 8 months ago
- ☆247Updated 4 years ago
- Go tool for managing Linux filesystem encryption☆1,002Updated 2 months ago
- Linux Kernel Sanitizers, fast bug-detectors for the Linux kernel☆469Updated 9 months ago
- The world's worst kernel module☆300Updated 4 years ago
- A lightweight sandbox tool for non-root users☆668Updated 7 years ago