
ansible-collection-hardening
This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

A horizontally scalable Direct Server Return layer 4 load balancer for Linux using XDP/eBPF

Linux 内核升级指南 - 修复 CVE-2026-64561

Linux 内核升级指南 - 修复 CVE-2026-53359

Hardened, Azure-optimized Linux distribution built from Fedora sources with RPM packaging, supply chain security, and declarative configuration for…

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

SSH bastion/jump host/jumpserver

eBPF-powered Linux observability with AI incident detection. AGPL-3.0 licensed.

Reference analysis of a Linux kernel Open vSwitch memory-corruption vulnerability, covering root cause, impact, detection commands, and mitigation…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.

Remediation task for CVE-2018-15686, CVE-2018-16866, and CVE-2018-16888 affecting SystemD in EL7

Generic kernel live patch for the KVM/x86 shadow-MMU use-after-free (Zapscape, CVE-2026-64561)

DaemonSet для митигации уязвимости CVE-2026-64564 (SCTPhantom)

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…