
nysm
eBPF-based stealth container that hides processes, sockets, eBPF objects, and audit logs from system monitoring tools, enabling covert…

eBPF-based stealth container that hides processes, sockets, eBPF objects, and audit logs from system monitoring tools, enabling covert…

Like Envoy xDS, but for eBPF filters

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…


Run untrusted AI code safely, fast

Open-source secret scanner in Rust

simply nodes and graphs

Your everyday Linux distribution gone Super Saiyan.

eBPF-based runtime security agent for Kubernetes that detects unknown processes and file changes, enforces pre-registered constraints, and automates…

Linux Persistence Detection, Hunting and Artifact Collection script

A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock

Suppress vulnerabilities applying Kubernetes context to scans

AIO Cloud Managment Server

CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication

Vulnerability as a service: showcasing CVS-2014-0160, a.k.a. Heartbleed

CLI tool that explains CVEs in plain English and scans repos for impact. Powered by Claude.

Exploit for Linux kernel CVE-2026-31431 causing page cache corruption via authencesn AEAD manipulation, targeting privilege escalation in containers…