
rustnet
Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

AWSGoat : A Damn Vulnerable AWS Infrastructure

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.

By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

the ps utility, with an eBPF twist and container context

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Open-source secret scanner in Rust

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Get process information straight from bash, minimal dependencies.

Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228

A tutorial on how to detect the CVE 2024-3094

Docker CVE-2022-37708