cloudflare / sandbox
Simple Linux seccomp rules without writing any code
☆458Updated last month
Related projects ⓘ
Alternatives and complementary repositories for sandbox
- A language and library for specifying syscall filtering policies.☆302Updated 3 months ago
- List of resources related to LD_PRELOAD, a mechanism for changing application behavior at run-time☆882Updated 6 months ago
- An easy way to virtualize the running system☆332Updated last year
- The main libseccomp repository☆808Updated last week
- sandboxing and containment tool used in ChromeOS and Android☆275Updated this week
- Linux Application Level Firewall based on eBPF and NFQUEUE.☆695Updated last year
- The reliability of disk images, the flexibility of files☆456Updated this week
- Light-weight Dynamic Tracer for Linux☆403Updated 2 months ago
- User-mode networking for unprivileged network namespaces☆746Updated 6 months ago
- A general purpose memory allocator that implements an isolation security strategy to mitigate memory safety issues while maintaining good…☆363Updated 4 months ago
- A dynamic library providing Virtualization-based process isolation capabilities☆916Updated this week
- Dump unix domain socket traffic with bpf☆364Updated 11 months ago
- BSD socket API on steroids☆275Updated last month
- run regular Docker images in KVM/Qemu☆804Updated 6 months ago
- Userspace eBPF VM☆833Updated this week
- firectl is a command-line tool to run Firecracker microVMs☆483Updated last month
- Dynamic Tracing in Linux☆976Updated 2 months ago
- A simple LD_PRELOAD library to disable SSL certificate verification. Inspired by libeatmydata.☆173Updated 6 years ago
- RLBox sandboxing framework☆287Updated 3 months ago
- Linux Kernel Runtime Guard☆414Updated 3 weeks ago
- Turn IP sockets into Unix domain sockets☆361Updated 4 months ago
- libeatmydata - because fsync() should be a no-op☆414Updated 6 months ago
- A lightweight sandbox tool for non-root users☆657Updated 6 years ago
- High-level tracing language for Linux eBPF - development moved to https://github.com/iovisor/bpftrace☆250Updated 5 years ago
- eBPF - extended Berkeley Packet Filter tooling☆122Updated 2 years ago
- FUSE implementation for overlayfs☆535Updated 3 months ago
- ☆594Updated last week
- A kernelspace syscall interceptor and randomized faulter☆350Updated this week
- Snuffy is a simple command line tool to inspect SSL/TLS data.☆290Updated 4 years ago