This tool set can generate SECCOMP profiles for Docker images. It mainly relies on static analysis, making its results more reliable than currently available tools.
☆72May 3, 2022Updated 4 years ago
Alternatives and similar repositories for confine
Users that are interested in confine are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This is the repository for the code and artifacts related to the CCS2022 paper: C2C: Fine-grained Configuration-driven System Call Filter…☆11Nov 4, 2022Updated 3 years ago
- This repository contains the source code related to the research paper titled "Temporal System Call Specialization for Attack Surface Red…☆40Nov 14, 2024Updated last year
- ☆26Jun 2, 2024Updated 2 years ago
- Analysis of syscall sequence pattern from exploit codes for advanced system call sequence filtering for enhanced container security☆16May 21, 2023Updated 3 years ago
- ☆11Feb 22, 2016Updated 10 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- agent for handling seccomp descriptors for container runtimes☆47Feb 1, 2024Updated 2 years ago
- ☆13Oct 17, 2021Updated 4 years ago
- BPFContain is a container security daemon for GNU/Linux leveraging the power and safety of eBPF and Rust.☆59Jun 30, 2022Updated 4 years ago
- Rust Language Bindings for the libseccomp Library☆48Jun 19, 2026Updated last month
- OCI hook to trace syscalls and generate a seccomp profile☆350Aug 2, 2026Updated last week
- Hodor for node.js☆15Jun 18, 2023Updated 3 years ago
- bouheki is KRSI(eBPF+LSM) based Linux security auditing tool.☆93Sep 21, 2025Updated 10 months ago
- Go library for installing a seccomp BPF system call filter.☆98Jul 19, 2026Updated 3 weeks ago
- Structured Information on State and Evolution of Dockerfiles - Online Appendix☆10Mar 16, 2018Updated 8 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Example BPF program with LSM hooks☆36Feb 24, 2021Updated 5 years ago
- Lepus-CTF frontend application☆12Nov 2, 2015Updated 10 years ago
- ☆22May 22, 2026Updated 2 months ago
- ☆25Dec 14, 2023Updated 2 years ago
- ☆40Feb 15, 2022Updated 4 years ago
- some kernel exploit challenges and cve analysis☆26Nov 30, 2018Updated 7 years ago
- ☆27Nov 24, 2021Updated 4 years ago
- bpflock - eBPF driven security for locking and auditing Linux machines☆157Feb 16, 2022Updated 4 years ago
- Orbit: OS Support for Safe and Efficient Auxiliary Tasks in Applications☆22May 23, 2022Updated 4 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆25Mar 2, 2024Updated 2 years ago
- BDA: Practical Dependence Analysis for Binary Executables by Unbiased Whole-program Path Sampling and Per-path Abstract Interpretation☆31Feb 26, 2021Updated 5 years ago
- Public repository for the paper "GodExpo: An Automated God Structure Detection Tool for Golang"☆13Feb 28, 2019Updated 7 years ago
- Streaming Generative AI Application on AWS☆14Jun 24, 2024Updated 2 years ago
- Use on-demand control- data- flow slicing combined with taint analysis and symbolic execution to produce scalable and precise UB detectio…☆26Sep 5, 2021Updated 4 years ago
- It's like DocBleach, but in your browser☆18Oct 24, 2019Updated 6 years ago
- mruby running inside the bare-metal hypervisor☆19Mar 8, 2020Updated 6 years ago
- Kubernetes controller for automated Node operations☆32Mar 16, 2026Updated 4 months ago
- A graph-based static-dynamic hybrid DEX code analysis tool☆42Apr 29, 2018Updated 8 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party Applications☆20May 6, 2024Updated 2 years ago
- A security-oriented static binary analysis tool for comparing the quantity and quality of code reuse gadget sets in program variants.☆18May 15, 2026Updated 2 months ago
- Asus AsIO2 Local Privilege Escalation exploit (based on ReWolf's MSI exploit)☆14Apr 5, 2020Updated 6 years ago
- An eBPF detection program for CVE-2022-0847☆29Jul 5, 2022Updated 4 years ago
- LoRaWAN session cracker - A PoC for exploiting weak or shared Application Keys☆19Jun 2, 2022Updated 4 years ago
- 从美国国家漏洞库NVD获取某个特定版本软件的漏洞统计信息。☆16Mar 29, 2022Updated 4 years ago
- Real-time web shop streaming analytics on AWS☆14Sep 18, 2024Updated last year