shamedgh / confineView external linksLinks
This tool set can generate SECCOMP profiles for Docker images. It mainly relies on static analysis, making its results more reliable than currently available tools.
☆70May 3, 2022Updated 3 years ago
Alternatives and similar repositories for confine
Users that are interested in confine are comparing it to the libraries listed below
Sorting:
- This is the repository for the code and artifacts related to the CCS2022 paper: C2C: Fine-grained Configuration-driven System Call Filter…☆11Nov 4, 2022Updated 3 years ago
- This repository contains the source code related to the research paper titled "Temporal System Call Specialization for Attack Surface Red…☆38Nov 14, 2024Updated last year
- ☆11Feb 22, 2016Updated 9 years ago
- ☆25Jun 2, 2024Updated last year
- This tool set can generate required capabilities for binaries. A system call to capability mapping is used to assign capability to the bi…☆14Oct 26, 2022Updated 3 years ago
- agent for handling seccomp descriptors for container runtimes☆47Feb 1, 2024Updated 2 years ago
- Analysis of syscall sequence pattern from exploit codes for advanced system call sequence filtering for enhanced container security☆16May 21, 2023Updated 2 years ago
- ☆13Oct 17, 2021Updated 4 years ago
- BPFContain is a container security daemon for GNU/Linux leveraging the power and safety of eBPF and Rust.☆59Jun 30, 2022Updated 3 years ago
- Streaming Generative AI Application on AWS☆14Jun 24, 2024Updated last year
- Keycloak gRPC extension☆12Mar 2, 2023Updated 2 years ago
- Dataset from Linux Raspian VMs and devices with auditd logs capturing various container escape and attacks.☆15Jul 30, 2022Updated 3 years ago
- OCI hook to trace syscalls and generate a seccomp profile☆337Updated this week
- Real-time web shop streaming analytics on AWS☆14Sep 18, 2024Updated last year
- ☆11May 16, 2024Updated last year
- Hodor for node.js☆15Jun 18, 2023Updated 2 years ago
- Lepus-CTF frontend application☆11Nov 2, 2015Updated 10 years ago
- Provides easy-to-use Linux seccomp-bpf jailing.☆105Feb 1, 2026Updated 2 weeks ago
- DSL language to write seccomp filters☆37Apr 5, 2024Updated last year
- bouheki is KRSI(eBPF+LSM) based Linux security auditing tool.☆92Sep 21, 2025Updated 4 months ago
- Asus AsIO2 Local Privilege Escalation exploit (based on ReWolf's MSI exploit)☆14Apr 5, 2020Updated 5 years ago
- Waffle is a library for integrating a Web Application Firewall (WAF) into Go applications.☆18Updated this week
- Kernel isolation tester.☆18Oct 20, 2022Updated 3 years ago
- Example BPF program with LSM hooks☆35Feb 24, 2021Updated 4 years ago
- Rust Language Bindings for the libseccomp Library☆45Apr 5, 2025Updated 10 months ago
- Automatic AppArmor management for Docker containers☆16Jul 22, 2023Updated 2 years ago
- It's like DocBleach, but in your browser☆18Oct 24, 2019Updated 6 years ago
- ☆15May 26, 2021Updated 4 years ago
- An API gateway plugin to introspect opaque access tokens and forward JWT access tokens to APIs☆18Feb 17, 2025Updated 11 months ago
- Exposing Keycloak metrics endpoints for Prometheus!☆15Aug 29, 2019Updated 6 years ago
- Keycloak provider implementation to support SIOP-2 clients and the issuance of VerifiableCredentials through the Account-Console.☆22Apr 24, 2024Updated last year
- A software to create endless-gif-loops from animation video files. / アニメの動画から無限ループgif動画を自動で生成する☆15Oct 20, 2020Updated 5 years ago
- A security-oriented static binary analysis tool for comparing the quantity and quality of code reuse gadget sets in program variants.☆17Oct 13, 2023Updated 2 years ago
- mruby running inside the bare-metal hypervisor☆19Mar 8, 2020Updated 5 years ago
- Use on-demand control- data- flow slicing combined with taint analysis and symbolic execution to produce scalable and precise UB detectio…☆25Sep 5, 2021Updated 4 years ago
- An eBPF detection program for CVE-2022-0847☆29Jul 5, 2022Updated 3 years ago
- TIRO - A hybrid iterative deobfuscation framework for Android applications☆27Aug 17, 2018Updated 7 years ago
- OpenID Shared Signals and Events (SSE) / Continuous Access Evaluation Protocol (CAEP) / Risk Incident Sharing and Coordination (RISC) JSO…☆14Jun 7, 2024Updated last year
- ClassicPlates Plus is an addon that adds additional features and new Classic-themed visuals to nameplates.☆10Oct 21, 2025Updated 3 months ago