Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
jailer — Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage maps and enforces role-based policies on file access, network operations, and process execution. | Kitploit
Tools/GitHubGitHub/gen0sec/jailer
Defensive ToolsContainer SecurityNetwork SecurityCloud Security
GitHubgen0sec/jailer

jailer

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage maps and enforces role-based policies on file access, network operations, and process execution.

View Repository
582116 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

Jailer - eBPF Mandatory Access Control

Warning: This project is under heavy development and is NOT ready for production use. APIs, policy formats, and behavior may change without notice. Use for testing and experimentation only.

Acknowledgments

Note: This is an independent implementation and is not the same project as Meta's solution. While BpfJailer is functionally similar and inspired by the original idea and design by Liam Wisehart, Justin Nga, Carl El Khoury, Mansee Chadha at Meta, this is a separate codebase developed independently. We extend our gratitude for the vision and foundational concepts that inspired this work.

Community

Join us on Discord Substack

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage maps and enforces role-based policies on file access, network operations, and process execution.

Features (Current Version)

FeatureStatusDescription
Process Tracking✅ WorkingTracks processes using task_storage BPF map
Socket Enrollment✅ WorkingProcesses enroll via Unix socket API
Role-based Policies✅ WorkingRestricted and permissive roles
File Access Control✅ WorkingBlock/allow file open operations
Jail Inheritance✅ WorkingChild processes inherit parent's jail
Network Control✅ WorkingBlock/allow socket bind/connect
Port/Protocol Filtering✅ WorkingPer-port TCP/UDP allow/deny rules
Exec Control✅ WorkingBlock/allow process execution
Path Matching✅ WorkingDentry walking with cache invalidation
Signed Binaries🚧 StubBinary signature validation (not implemented)
Alternative Enrollment✅ WorkingAuto-enroll by executable, cgroup, or xattr
Daemonless Mode✅ WorkingBootstrap binary pins programs at early boot
Audit Events✅ WorkingPerf buffer for systemd-journald integration

Nginx demo

Nginx demo

Complex demo

asciicast

Kernel Requirements

Minimum Kernel Version

  • Linux 5.11+ (for BPF_MAP_TYPE_TASK_STORAGE support)
  • Recommended: Linux 6.1+ (better BTF support)

Required Kernel Configuration

# Check current kernel config
zcat /proc/config.gz 2>/dev/null || cat /boot/config-$(uname -r)

Required options:

CONFIG_BPF=y
CONFIG_BPF_SYSCALL=y
CONFIG_BPF_LSM=y
CONFIG_DEBUG_INFO_BTF=y

Enable BPF LSM

BPF LSM must be enabled in the kernel boot parameters:

# Check if BPF LSM is active
cat /sys/kernel/security/lsm
# Should include "bpf" in the list

# If not, add to kernel boot parameters:
# Edit /etc/default/grub and add to GRUB_CMDLINE_LINUX:
#   lsm=lockdown,capability,landlock,yama,apparmor,bpf

# Then update grub and reboot:
sudo update-grub
sudo reboot

For Ubuntu/Debian systems, you can also use:

# Create a script to enable BPF LSM
cat > /tmp/enable_bpf_lsm.sh << 'EOF'
#!/bin/bash
GRUB_FILE="/etc/default/grub"
if grep -q "lsm=" "$GRUB_FILE"; then
    sudo sed -i 's/lsm=[^""]*/lsm=lockdown,capability,landlock,yama,apparmor,bpf/' "$GRUB_FILE"
else
    sudo sed -i 's/GRUB_CMDLINE_LINUX="\(.*\)"/GRUB_CMDLINE_LINUX="\1 lsm=lockdown,capability,landlock,yama,apparmor,bpf"/' "$GRUB_FILE"
fi
sudo update-grub
echo "BPF LSM enabled. Please reboot."
EOF
chmod +x /tmp/enable_bpf_lsm.sh
sudo /tmp/enable_bpf_lsm.sh

Build

Prerequisites

# Install Rust
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

# Install build dependencies (Ubuntu/Debian)
sudo apt-get install -y clang llvm libelf-dev linux-headers-$(uname -r)

# Install BPF target for Rust
rustup target add bpfel-unknown-none

Build All Components

cd bpfjail

# Build BPF programs
cd bpfjailer-bpf && cargo build --release && cd ..

# Build daemon and client
cargo build --release

Quick Start

1. Start the Daemon

# Run as root (loads config/policy.json if present)
sudo RUST_LOG=info ./target/release/bpfjailer-daemon

Expected output:

[INFO] BpfJailer daemon starting...
[INFO] Loading BpfJailer eBPF programs with libbpf-rs...
[INFO] ✓ pending_enrollments map available for enrollment
[INFO] ✓ network_rules map available for port/protocol filtering
[INFO] ✓ task_storage map created successfully
[INFO] ✓ Program task_alloc attached
[INFO] ✓ Program file_open attached
[INFO] ✓ Program socket_bind attached
[INFO] ✓ Program socket_connect attached
[INFO] ✓ Program bprm_check_security attached
[INFO] Initialized with default roles: restricted (1), permissive (2)
[INFO] Loaded policy from config/policy.json
[INFO] Loaded 5 roles
[INFO] Enrollment server listening on /run/bpfjailer/enrollment.sock

2. Run Security Tests

# Run vulnerability tests WITHOUT jailing (shows attacks succeed)
sudo python3 tests/vulnerable_apps/run_tests.py

# Run vulnerability tests WITH restricted role (shows attacks blocked)
sudo python3 tests/vulnerable_apps/run_tests.py --role 1

# Run specific test
sudo python3 tests/vulnerable_apps/run_tests.py --role 1 --test path

# List available tests and roles
sudo python3 tests/vulnerable_apps/run_tests.py --list

Example output with restricted role:

============================================================
TEST: Path Traversal / Arbitrary File Read
============================================================
Attempting to read /etc/passwd via path traversal...
BLOCKED - Permission denied (BpfJailer blocked file access)

============================================================
TEST: Command Injection
============================================================
Attempting command injection...
BLOCKED - Permission denied (BpfJailer blocked exec)

============================================================
TEST: Reverse Shell / Data Exfiltration
============================================================
Test 1: Reverse shell connection to 127.0.0.1:4444
BLOCKED - Permission denied (BpfJailer blocked connect)

Available Security Tests

TestVulnerabilityMitigated By
path_traversalArbitrary file read via ../restricted, isolated
command_injectionShell command executionrestricted, webserver, isolated
reverse_shellOutbound connections to attackerrestricted, isolated
ssrfAccess internal services/cloud metadatarestricted, isolated
arbitrary_writeWrite to sensitive pathsrestricted
crypto_minerDownload + execute + connect to poolrestricted, webserver
privilege_escalationRead shadow, write sudoersrestricted

3. Manual Enrollment Test

#!/usr/bin/env python3
import socket
import json
import os

# Connect to daemon
sock = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM)
sock.connect("/run/bpfjailer/enrollment.sock")

# Enroll with restricted role (ID 1)
request = {"Enroll": {"pod_id": 1, "role_id": 1}}
sock.send((json.dumps(request) + "\n").encode())
response = sock.recv(4096).decode()
print(f"Enrollment: {response}")
sock.close()

# Try to read a file (should be blocked)
try:
    open("/etc/passwd").read()
    print("File access: ALLOWED")
except PermissionError:
    print("File access: BLOCKED")

Policy File

BpfJailer loads roles from a JSON policy file. The daemon searches for the policy file in this order:

Download Tool