containers / oci-seccomp-bpf-hook
OCI hook to trace syscalls and generate a seccomp profile
☆309Updated 2 weeks ago
Alternatives and similar repositories for oci-seccomp-bpf-hook:
Users that are interested in oci-seccomp-bpf-hook are comparing it to the libraries listed below
- Making containers more secure with eBPF and Linux Security Modules (LSM)☆224Updated 8 months ago
- agent for handling seccomp descriptors for container runtimes☆44Updated last year
- 🐝 BPFBox 📦 Exploring process confinement in eBPF☆101Updated last year
- The Kubernetes Security Profiles Operator☆743Updated this week
- A tool for in-depth analysis of container checkpoints☆106Updated 2 weeks ago
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆256Updated this week
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- bpflock - eBPF driven security for locking and auditing Linux machines☆142Updated 3 years ago
- Now moved into `github.com/inspektor-gadget/inspektor-gadget/pkg/gadget-collection/gadgets/traceloop`. Tracing system calls in cgroups u…☆198Updated last year
- Generate a variety of suspect actions that are detected by Falco rulesets☆101Updated this week
- Source-code based coverage for eBPF programs actually running in the Linux kernel☆130Updated 2 weeks ago
- ptrace-based event producer for udig☆67Updated 2 years ago
- Encryption libraries for Encrypted OCI Container images☆152Updated 2 months ago
- Community curated list of System and Network policy templates for the KubeArmor and Cilium☆42Updated 2 weeks ago
- eBPF & Cilium Office Hours☆316Updated 2 months ago
- Build custom Docker seccomp profiles for containers by finding syscalls it uses.☆89Updated 4 years ago
- Artifact Ratification Framework (CNCF Sandbox)☆248Updated this week
- SELinux policy files for Container Runtimes☆263Updated last week
- Response Engine for managing threats in your Kubernetes☆148Updated this week
- Tools for understanding, measuring, and applying network policies effectively in kubernetes☆114Updated 7 months ago
- Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supp…☆126Updated last week
- An eBPF program debugger☆200Updated 2 years ago
- Linux Process Discovery. C Library, Go bindings, Runtime.☆219Updated 2 years ago
- A file system events notifier based on eBPF☆61Updated last year
- An eBPF Manager for Linux and Kubernetes☆572Updated this week
- A replacement for "kubectl exec" that works over WebSocket connections.☆36Updated 10 months ago
- ebpf.io Website☆120Updated last week
- A process level network security monitoring and enforcement project for Kubernetes, using eBPF☆42Updated 4 years ago
- Operator to deploy confidential containers runtime☆120Updated last week
- Manage admission policies in your Kubernetes cluster with ease☆202Updated this week