google / nsjail
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,125Updated last month
Alternatives and similar repositories for nsjail:
Users that are interested in nsjail are comparing it to the libraries listed below
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆4,110Updated 3 months ago
- Checkpoint/Restore tool☆3,092Updated last week
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,516Updated 5 years ago
- Linux namespaces and seccomp-bpf sandbox☆5,990Updated this week
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆5,529Updated this week
- High-level tracing language for Linux☆8,934Updated this week
- like ~~grep~~ UBER, but for binaries☆1,724Updated 2 years ago
- A foreign function interface for bash.☆2,114Updated 7 months ago
- Browser-based frontend to gdb (gnu debugger). Add breakpoints, view the stack, visualize data structures, and more in C, C++, Go, Rust, a…☆10,002Updated 11 months ago
- A userspace out-of-memory killer☆1,851Updated this week
- Painless relocation of Linux binaries–and all of their dependencies–without containers.☆2,952Updated last year
- Programmable debugger☆1,841Updated this week
- Record and Replay Framework☆9,481Updated last week
- Porting Windows Dynamic Link Libraries to Linux☆4,362Updated 10 months ago
- Content-Addressable Data Synchronization Tool☆1,512Updated last year
- Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)☆3,130Updated last month
- Embeddable, replicated and fault-tolerant SQL engine.☆3,956Updated last week
- unfork(2) is the inverse of fork(2). sort of.☆1,473Updated 10 months ago
- Binary Optimization and Layout Tool - A linux command-line utility used for optimizing performance of binaries☆2,527Updated last year
- Linux system exploration and troubleshooting tool with first class support for containers☆7,917Updated this week
- Wrangling Untrusted File Formats Safely☆4,273Updated last week
- GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Li…☆7,257Updated last week
- Application Kernel for Containers☆16,107Updated this week
- A Virtual Machine Monitor for modern Cloud workloads. Features include CPU, memory and device hotplug, support for running Windows and Li…☆4,305Updated this week
- Learn where some of the network sysctl variables fit into the Linux/Kernel network flow. Translations: 🇷🇺☆5,606Updated 3 weeks ago
- jq for binary formats - tool, language and decoders for working with binary and text formats☆9,926Updated this week
- The main libseccomp repository☆823Updated 3 weeks ago
- Ignite a Firecracker microVM☆3,492Updated last year
- A linux-based assembly REPL for x86, amd64, armv7, and armv8☆1,181Updated 11 months ago
- Simple Linux seccomp rules without writing any code☆470Updated 4 months ago