google / nsjail
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,182Updated 3 weeks ago
Alternatives and similar repositories for nsjail:
Users that are interested in nsjail are comparing it to the libraries listed below
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆4,236Updated 5 months ago
- OSv, a new operating system for the cloud.☆4,158Updated last week
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,518Updated 5 years ago
- Content-Addressable Data Synchronization Tool☆1,516Updated last year
- Linux system exploration and troubleshooting tool with first class support for containers☆7,968Updated last month
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆5,616Updated this week
- Application Kernel for Containers☆16,333Updated this week
- High-level tracing language for Linux☆9,093Updated this week
- The main libseccomp repository☆836Updated 3 weeks ago
- A toolkit for building secure, portable and lean operating systems for containers☆8,412Updated last month
- A userspace out-of-memory killer☆1,867Updated this week
- Wrangling Untrusted File Formats Safely☆4,469Updated 3 weeks ago
- The Unikernel & MicroVM Compilation and Deployment Platform☆2,740Updated last year
- Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)☆3,165Updated this week
- Programmable debugger☆1,865Updated this week
- OSS-Fuzz - continuous fuzzing for open source software.☆10,964Updated this week
- Record and Replay Framework☆9,679Updated this week
- BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more☆21,189Updated this week
- A hacky debugger UI for hackers☆6,245Updated 2 months ago
- A kernel designed to run one and only one application in a virtualized environment☆2,751Updated last week
- A foreign function interface for bash.☆2,127Updated 9 months ago
- UNIX-like reverse engineering framework and command-line toolset.☆2,867Updated last week
- unfork(2) is the inverse of fork(2). sort of.☆1,473Updated 11 months ago
- Checked C is an extension to C that lets programmers write C code with bounds checking and improved type-safety. The goal is to let peopl…☆3,230Updated 6 months ago
- High-performance regular expression matching library☆4,942Updated last week
- Painless relocation of Linux binaries–and all of their dependencies–without containers.☆2,954Updated last year
- firecracker-containerd enables containerd to manage containers as Firecracker microVMs☆2,324Updated 3 weeks ago
- Ignite a Firecracker microVM☆3,493Updated last year
- Embeddable, replicated and fault-tolerant SQL engine.☆4,007Updated this week
- A high performance layer 4 load balancer☆4,914Updated this week