google / nsjail
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,034Updated last week
Alternatives and similar repositories for nsjail:
Users that are interested in nsjail are comparing it to the libraries listed below
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆4,050Updated 2 months ago
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆5,487Updated this week
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,515Updated 5 years ago
- Linux system exploration and troubleshooting tool with first class support for containers☆7,833Updated last month
- A foreign function interface for bash.☆2,112Updated 6 months ago
- Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)☆3,112Updated last week
- Application Kernel for Containers☆16,010Updated this week
- Checkpoint/Restore tool☆3,048Updated last week
- OSS-Fuzz - continuous fuzzing for open source software.☆10,750Updated this week
- A transparent, highly scalable and cryptographically verifiable data store.☆3,585Updated this week
- Ignite a Firecracker microVM☆3,494Updated last year
- A kernel designed to run one and only one application in a virtualized environment☆2,687Updated last week
- like ~~grep~~ UBER, but for binaries☆1,720Updated last year
- Wrangling Untrusted File Formats Safely☆4,244Updated last month
- Record and Replay Framework☆9,278Updated this week
- A hacky debugger UI for hackers☆6,180Updated 6 months ago
- Checksec☆2,088Updated 2 weeks ago
- unfork(2) is the inverse of fork(2). sort of.☆1,471Updated 8 months ago
- Embeddable, replicated and fault-tolerant SQL engine.☆3,936Updated last month
- A minimal init system for Linux containers☆6,963Updated 3 weeks ago
- High-level tracing language for Linux☆8,841Updated this week
- A userspace out-of-memory killer☆1,837Updated 2 months ago
- A linux-based assembly REPL for x86, amd64, armv7, and armv8☆1,168Updated 10 months ago
- Userspace WireGuard® Implementation in Rust☆6,215Updated 3 months ago
- A ssh server that knows who you are. $ ssh whoami.filippo.io☆2,242Updated 5 months ago
- A toolkit for building secure, portable and lean operating systems for containers☆8,339Updated this week
- Standalone, daemon-less, unprivileged Dockerfile and OCI compatible container image builder.☆3,921Updated 7 months ago
- Docker implemented in around 100 lines of bash☆12,141Updated 7 years ago
- High-performance regular expression matching library☆4,876Updated 8 months ago
- chw00t - Unices chroot breaking tool☆569Updated 5 years ago