
ptcpdump
eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Let your AI go full send. Your home directory stays home.

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

a guard that blocks catastrophic agent actions

Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…

A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing



Run untrusted AI code safely, fast

Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

Qubes containerization on Windows

Firecracker made simple. Spin up secure microVMs in milliseconds, from install to interactive shell in one command.

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…