google / nsjail
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,203Updated last month
Alternatives and similar repositories for nsjail:
Users that are interested in nsjail are comparing it to the libraries listed below
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆4,280Updated 6 months ago
- Record and Replay Framework☆9,774Updated last week
- Linux namespaces and seccomp-bpf sandbox☆6,228Updated this week
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,519Updated 5 years ago
- unfork(2) is the inverse of fork(2). sort of.☆1,473Updated last year
- Checkpoint/Restore tool☆3,213Updated last week
- like ~~grep~~ UBER, but for binaries☆1,728Updated 2 years ago
- High-level tracing language for Linux☆9,167Updated this week
- Embeddable, replicated and fault-tolerant SQL engine.☆4,015Updated this week
- Ignite a Firecracker microVM☆3,493Updated last year
- Wrangling Untrusted File Formats Safely☆4,483Updated last week
- A userspace out-of-memory killer☆1,899Updated this week
- The main libseccomp repository☆846Updated last month
- Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)☆3,174Updated 3 weeks ago
- Linux system exploration and troubleshooting tool with first class support for containers☆7,982Updated last month
- A Virtual Machine Monitor for modern Cloud workloads. Features include CPU, memory and device hotplug, support for running Windows and Li…☆4,443Updated this week
- A foreign function interface for bash.☆2,134Updated 10 months ago
- OSv, a new operating system for the cloud.☆4,163Updated this week
- Content-Addressable Data Synchronization Tool☆1,518Updated last year
- go-audit is an alternative to the auditd daemon that ships with many distros☆1,621Updated 2 weeks ago
- BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more☆21,286Updated last week
- Unix command line queue utility☆2,988Updated 10 months ago
- Painless relocation of Linux binaries–and all of their dependencies–without containers.☆2,953Updated last year
- 🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc.☆3,853Updated last week
- Userspace WireGuard® Implementation in Rust☆6,363Updated last week
- A linux-based assembly REPL for x86, amd64, armv7, and armv8☆1,201Updated last year
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆5,649Updated this week
- A kernel designed to run one and only one application in a virtualized environment☆2,771Updated 3 weeks ago
- A curated list of awesome projects related to eBPF.☆4,562Updated last month
- tiniest x86-64-linux emulator☆7,153Updated last month