173 results for “topic:seccomp”
Slim(toolkit): Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
Sandstorm is a self-hostable web productivity suite. It's implemented as a security-hardened web app package manager. | Actively sponsored by our friends at TestMu AI
Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.
Provide powerful tools for seccomp analysis
A stupid game for learning about containers, capabilities, and syscalls.
The main libseccomp repository
The Kubernetes Security Profiles Operator
Lightweight, container-free sandbox for running commands with network and filesystem restrictions
vArmor is a cloud native container sandbox system based on AppArmor/BPF/Seccomp. It also includes multiple built-in protection rules that are ready to use out of the box.
Tool and framework for securely reading untrusted USB mass storage devices.
minT(oolkit): Mint awesome, secure and production ready containers just the way you need them! Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
The libseccomp golang bindings repository
A set of curated exercises to help you prepare for the CKS exam
Library-Level eBPF Sandbox for Python (Linux & macOS): syscall-level control per module.
🔍 Function-level tracing tool for Seccomp profiling, with eBPF
Rust implementation of PRoot, a ptrace-based sandbox
Generate seccomp profiles from go binaries
Simplifying Seccomp enforcement in containerized or non-containerized apps
Provides easy-to-use Linux seccomp-bpf jailing.
Build custom Docker seccomp profiles for containers by finding syscalls it uses.
Go library for installing a seccomp BPF system call filter.
A tool to resolve seccomp just like seccomp-tools, written in C
Process isolation for Linux using namespaces, resource limits, cgroups, landlock and seccomp.
Record process launches and files read and written by each process
BPF Processor for IDA Python
Docker Secure Computing Profile Generator
Control plane for system processes
A CSP endpoint to aggregate, correlate and analyze report-uri violations across your infrastructure
📦 Run untrusted python code on the server.
agent for handling seccomp descriptors for container runtimes