google / nsjailLinks
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,684Updated 3 weeks ago
Alternatives and similar repositories for nsjail
Users that are interested in nsjail are comparing it to the libraries listed below
Sorting:
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆5,606Updated last week
- Application Kernel for Containers☆17,595Updated last week
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆6,033Updated this week
- A Virtual Machine Monitor for modern Cloud workloads. Features include CPU, memory and device hotplug, support for running Windows and Li…☆5,209Updated this week
- A kernel designed to run one and only one application in a virtualized environment☆3,049Updated last week
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,519Updated 6 years ago
- Linux namespaces and seccomp-bpf sandbox☆6,983Updated this week
- Checkpoint/Restore tool☆3,664Updated this week
- Linux system exploration and troubleshooting tool with first class support for containers☆8,186Updated this week
- Simple Linux seccomp rules without writing any code☆515Updated 7 months ago
- firecracker-containerd enables containerd to manage containers as Firecracker microVMs☆2,647Updated 3 weeks ago
- The main libseccomp repository☆895Updated 3 weeks ago
- Ignite a Firecracker microVM☆3,530Updated 2 years ago
- A foreign function interface for bash.☆2,157Updated last month
- A fast and lightweight fully featured OCI runtime and C library for running containers☆3,757Updated this week
- Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)☆3,299Updated 3 weeks ago
- Generate sandboxes for C/C++ libraries automatically☆1,726Updated 3 months ago
- OSv, a new operating system for the cloud.☆4,223Updated last month
- Wrangling Untrusted File Formats Safely☆4,701Updated 2 months ago
- Programmable debugger☆1,964Updated last week
- weggli is a fast and robust semantic search tool for C and C++ codebases. It is designed to help security researchers identify interestin…☆2,474Updated last year
- Content-Addressable Data Synchronization Tool☆1,563Updated 4 months ago
- kpatch - live kernel patching☆1,657Updated last week
- A userspace out-of-memory killer☆2,009Updated 3 weeks ago
- Record and Replay Framework☆10,352Updated 2 weeks ago
- The Unikernel & MicroVM Compilation and Deployment Platform☆2,795Updated 2 years ago
- Painless relocation of Linux binaries–and all of their dependencies–without containers.☆3,006Updated 2 years ago
- Embeddable, replicated and fault-tolerant SQL engine.☆4,268Updated last week
- A simple SSL/TLS proxy with mutual authentication for securing non-TLS services.☆2,120Updated 3 weeks ago
- A high performance layer 4 load balancer☆5,174Updated this week