
amla-sandbox
WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…

WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…

A collection of scripts, and tips and tricks for hacking k8s clusters and containers.

Black-box Kubernetes attack surface discovery tool that probes for unsecured clusters, exposed dashboards, and misconfigurations using…

eBPF-powered silent observer for containerized runtimes, built for malware analysis sandboxes and Agentic AI monitoring.

eBPF-driven security tool for locking and auditing Linux machines. Restricts kernel features, blocks fileless execution, protects memory, and hardens…

the ps utility, with an eBPF twist and container context

Ultrafast CLI on Apple Silicon macOS for fast, sandboxed development and LLM agents.

The only open-source tool to analyze vulnerabilities and configuration issues with running docker container(s) and docker networks.

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Pentester-focused Docker registry tool to enumerate and pull images

PoC and Detection for CVE-2024-21626

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.

Cloud-native system telemetry pipeline that collects, processes, and exports system call events into a compact object-relational format for…

eBPF-based runtime security agent for Kubernetes that detects unknown processes and file changes, enforces pre-registered constraints, and automates…

Linux Persistence Detection, Hunting and Artifact Collection script

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

NTPD remote DOS exploit and vulnerable container