
minimal
Minimal CVE Hardened container image collection

Minimal CVE Hardened container image collection

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Vulnerable app with examples showing how to not use secrets

A security-focused library OS supporting kernel- and user-mode execution

An egress firewall for untrusted workloads.

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

Linux, macOS and Windows Install scripts for cnquery & cnspec

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Run Windows inside a Docker container with KVM acceleration, automatic installation, and customizable resources. Supports multiple Windows versions,…

Proof-of-concept demonstrating a path traversal vulnerability (CVE-2026-35204) in Helm plugin installation, allowing arbitrary file write via crafted…

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

Kubernetes-native security operator that automates vulnerability scanning, configuration auditing, secret detection, RBAC analysis, and compliance…

Deliberately vulnerable Docker lab reproducing CVE-2026-33634: LiteLLM gateway SSRF via api_base plus a trojanized dependency, with a multi-phase…