kinvolk / seccompagent
agent for handling seccomp descriptors for container runtimes
☆45Updated last year
Alternatives and similar repositories for seccompagent:
Users that are interested in seccompagent are comparing it to the libraries listed below
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated last week
- Find your favorite eBee☆61Updated 2 months ago
- ☆25Updated 10 months ago
- Making containers more secure with eBPF and Linux Security Modules (LSM)☆224Updated 9 months ago
- A replacement for "kubectl exec" that works over WebSocket connections.☆36Updated 11 months ago
- Evolution process of The Falco Project☆50Updated this week
- Shape your traffic the BPF way☆79Updated last year
- Source-code based coverage for eBPF programs actually running in the Linux kernel☆130Updated last month
- A tool for in-depth analysis of container checkpoints☆110Updated last week
- ☆74Updated 3 months ago
- ptrace-based event producer for udig☆67Updated 2 years ago
- 🐝 BPFBox 📦 Exploring process confinement in eBPF☆101Updated last year
- An query language and interactive tooling to work with SBOM data.☆14Updated 5 months ago
- sigstore the hard way!☆110Updated 10 months ago
- Falco plugins registry☆89Updated this week
- Discover least permissive security posture, Network Microsegmentation, and Application behaviour based on visibility/observability data e…☆32Updated last year
- Administrative tooling for Falco☆93Updated this week
- OCI hook to trace syscalls and generate a seccomp profile☆312Updated last week
- A process level network security monitoring and enforcement project for Kubernetes, using eBPF☆42Updated 4 years ago
- bpflock - eBPF driven security for locking and auditing Linux machines☆146Updated 3 years ago
- [Experimental] jail for Go modules☆75Updated this week
- Add oci hooks to Docker☆62Updated last year
- This repository contains various code snippets and learnings around eBPF☆82Updated 9 months ago
- Operator to deploy confidential containers runtime☆125Updated last week
- Runtime security plug to protect user containers☆65Updated last month
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Library to work with linux namespaces in go☆35Updated last year
- Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supp…☆128Updated last week
- Code coverage tooling for eBPF☆36Updated 7 months ago
- Fine-grained, zero-trust workload identity & access control☆68Updated 8 months ago