google / nsjailLinks
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,614Updated 3 weeks ago
Alternatives and similar repositories for nsjail
Users that are interested in nsjail are comparing it to the libraries listed below
Sorting:
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆5,238Updated 4 months ago
- Linux namespaces and seccomp-bpf sandbox☆6,852Updated this week
- Application Kernel for Containers☆17,370Updated this week
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆5,967Updated this week
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,520Updated 6 years ago
- Ignite a Firecracker microVM☆3,523Updated 2 years ago
- The main libseccomp repository☆888Updated 2 months ago
- Linux system exploration and troubleshooting tool with first class support for containers☆8,159Updated 2 weeks ago
- Checkpoint/Restore tool☆3,550Updated last week
- Simple Linux seccomp rules without writing any code☆513Updated 5 months ago
- A kernel designed to run one and only one application in a virtualized environment☆3,024Updated this week
- firecracker-containerd enables containerd to manage containers as Firecracker microVMs☆2,592Updated last week
- Checksec☆2,254Updated last week
- A fast and lightweight fully featured OCI runtime and C library for running containers☆3,684Updated last week
- A userspace out-of-memory killer☆2,003Updated this week
- Generate sandboxes for C/C++ libraries automatically☆1,723Updated 2 months ago
- Programmable debugger☆1,946Updated last week
- A simple SSL/TLS proxy with mutual authentication for securing non-TLS services.☆2,110Updated last week
- A Virtual Machine Monitor for modern Cloud workloads. Features include CPU, memory and device hotplug, support for running Windows and Li…☆5,077Updated this week
- High-level tracing language for Linux☆9,825Updated this week
- Embeddable, replicated and fault-tolerant SQL engine.☆4,248Updated last week
- Content-Addressable Data Synchronization Tool☆1,553Updated 3 months ago
- BPF Tools - packet analyst toolkit☆1,224Updated last year
- The Unikernel & MicroVM Compilation and Deployment Platform☆2,786Updated 2 years ago
- Linux-native "fake root" for implementing rootless containers☆1,180Updated last week
- Shadow is a discrete-event network simulator that directly executes real application code, enabling you to simulate distributed systems w…☆1,638Updated last week
- Custom & better AppArmor profile generator for Docker containers.☆1,224Updated 5 years ago
- Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)☆3,286Updated 3 months ago
- GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Li…☆7,922Updated 2 weeks ago
- Record and Replay Framework☆10,293Updated this week