
litebox
A security-focused library OS supporting kernel- and user-mode execution

A security-focused library OS supporting kernel- and user-mode execution

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

Port Scanner with Docker & Prometheus + Grafana integration. A tool for network auditing with multithreading support and real-time monitoring.

webapp vulnerable to CVE-2021-44228

Open Source Cloud Native Application Protection Platform (CNAPP)

Run any command inside a restricted filesystem view on Linux


Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…