cloudflare / sandboxLinks
Simple Linux seccomp rules without writing any code
☆507Updated 4 months ago
Alternatives and similar repositories for sandbox
Users that are interested in sandbox are comparing it to the libraries listed below
Sorting:
- A language and library for specifying syscall filtering policies.☆336Updated last month
- List of resources related to LD_PRELOAD, a mechanism for changing application behavior at run-time☆903Updated last year
- sandboxing and containment tool used in ChromeOS and Android☆339Updated this week
- A general purpose memory allocator that implements an isolation security strategy to mitigate memory safety issues while maintaining good…☆382Updated last year
- Linux Application Level Firewall based on eBPF and NFQUEUE.☆703Updated 2 years ago
- User-mode networking for unprivileged network namespaces☆864Updated 5 months ago
- Dump unix domain socket traffic with bpf☆412Updated last year
- The main libseccomp repository☆880Updated last month
- Light-weight Dynamic Tracer for Linux☆424Updated 2 months ago
- An easy way to virtualize the running system☆351Updated 2 years ago
- eBPF - extended Berkeley Packet Filter tooling☆125Updated 3 years ago
- Sandboxing File System☆46Updated 5 years ago
- libeatmydata - because fsync() should be a no-op☆461Updated last year
- BSD socket API on steroids☆316Updated last year
- The reliability of disk images, the flexibility of files☆585Updated 2 weeks ago
- ☆276Updated last year
- Scripts to slightly improve the security of the Linux boot process with UEFI Secure Boot and TPM support☆282Updated 2 years ago
- A dynamic library providing Virtualization-based process isolation capabilities☆1,311Updated last week
- Dynamic Tracing in Linux☆1,019Updated 2 months ago
- Turn IP sockets into Unix domain sockets☆371Updated last year
- Libraries to abstract aspects of working with TPMs for the purposes of attestation☆403Updated 2 weeks ago
- Linux kernel - See Landlock issues☆43Updated 6 months ago
- A kernelspace syscall interceptor and randomized faulter☆355Updated 11 months ago
- KernelMemorySanitizer, a detector of uses of uninitialized memory in the Linux kernel☆417Updated 7 months ago
- ☆650Updated last week
- Linux in Unikernel Clothing☆72Updated 4 years ago
- Snuffy is a simple command line tool to inspect SSL/TLS data.☆292Updated 5 years ago
- Unikernel Linux☆225Updated 2 months ago
- Userspace eBPF VM☆928Updated this week
- opensnoop in pure C using eBPF☆102Updated 6 months ago