Here are
75 public repositories
matching this topic...
DockerSlim (docker-slim): Don't change anything in your Docker container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.
Updated
Jun 4, 2021
AGS Script
A stupid game for learning about containers, capabilities, and syscalls.
Updated
Sep 17, 2020
JavaScript
Provide powerful tools for seccomp analysis
Updated
Jul 24, 2021
Ruby
The main libseccomp repository
The libseccomp golang bindings repository
The Kubernetes Security Profiles Operator
Generate seccomp profiles from go binaries
Simplifying Seccomp enforcement in containerized or non-containerized apps
Build custom Docker seccomp profiles for containers by finding syscalls it uses.
Updated
Aug 17, 2020
Python
Rust implementation of PRoot, a ptrace-based sandbox
Updated
Jul 24, 2021
Rust
Go library for installing a seccomp BPF system call filter.
Record process launches and files read and written by each process
BPF Processor for IDA Python
Updated
Aug 27, 2018
Python
Docker Secure Computing Profile Generator
Going Florida on container keyring masks. A tool to demonstrate the ineffectivity containers have on isolating Linux Kernel keyrings.
A high scalable low to medium interactive SSH/TCP honeypot using Linux Namespaces, capabilities, seccomp, cgroups designed for OpenWrt and IoT devices.
Online Judge for testing programming ability in C, C++, Java and Python.
Updated
Jun 29, 2021
JavaScript
A CSP endpoint to aggregate, correlate and analyze report-uri violations across your infrastructure
Updated
Feb 17, 2020
Python
Start Linux programs with only selected syscalls enabled (libseccomp-based)
Simple seccomp library for rust
Updated
Jan 19, 2021
Rust
A portable version of OpenBSD's privsep/sandboxed file(1) utility
DSL language to write seccomp filters
xinetd-kafel is a more secure replacement for xinetd with secure computing (seccomp, only work on linux)
🔒 download, verify & run torbrowser in a sandbox
Updated
Jul 20, 2021
Shell
Go VirtualBox vboxsf sendfile bug workaround
agent for handling seccomp descriptors for container runtimes
strace2seccomp - generates libseccomp policies from strace logs
A command line tool to automatically generate seccomp profiles.
low-level bindings to libseccomp
Improve this page
Add a description, image, and links to the
seccomp
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
seccomp
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.