google / nsjailLinks
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,704Updated last week
Alternatives and similar repositories for nsjail
Users that are interested in nsjail are comparing it to the libraries listed below
Sorting:
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆5,695Updated this week
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆6,033Updated this week
- A Virtual Machine Monitor for modern Cloud workloads. Features include CPU, memory and device hotplug, support for running Windows and Li…☆5,238Updated this week
- Ignite a Firecracker microVM☆3,530Updated 2 years ago
- The main libseccomp repository☆897Updated last month
- Generate sandboxes for C/C++ libraries automatically☆1,726Updated 3 months ago
- A kernel designed to run one and only one application in a virtualized environment☆3,054Updated last week
- Simple Linux seccomp rules without writing any code☆516Updated 7 months ago
- Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)☆3,304Updated last month
- A fast and lightweight fully featured OCI runtime and C library for running containers☆3,757Updated last week
- firecracker-containerd enables containerd to manage containers as Firecracker microVMs☆2,647Updated last month
- Linux namespaces and seccomp-bpf sandbox☆7,010Updated this week
- Programmable debugger☆1,966Updated this week
- The Unikernel & MicroVM Compilation and Deployment Platform☆2,796Updated 2 years ago
- Linux-native "fake root" for implementing rootless containers☆1,189Updated 3 weeks ago
- Painless relocation of Linux binaries–and all of their dependencies–without containers.☆3,006Updated 2 years ago
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,520Updated 6 years ago
- Content-Addressable Data Synchronization Tool☆1,566Updated 4 months ago
- A userspace out-of-memory killer☆2,012Updated 3 weeks ago
- OSv, a new operating system for the cloud.☆4,229Updated last month
- Record and Replay Framework☆10,362Updated 3 weeks ago
- A transparent, highly scalable and cryptographically verifiable data store.☆3,699Updated this week
- A linux-based assembly REPL for x86, amd64, armv7, and armv8☆1,255Updated last year
- Checkpoint/Restore tool☆3,673Updated this week
- 💽 Build Bespoke OS Images☆1,752Updated this week
- A dynamic library providing Virtualization-based process isolation capabilities☆1,533Updated last week
- chw00t - Unices chroot breaking tool☆613Updated 6 years ago
- Snabb: Simple and fast packet networking☆3,031Updated last year
- Linux Kernel Defence Map shows the relationships between vulnerability classes, exploitation techniques, bug detection mechanisms, and de…☆2,257Updated last month
- MirageOS is a library operating system that constructs unikernels☆2,832Updated last week