
rustnet
Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Chaos testing, network emulation, and stress testing tool for containers

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

Proof-of-concept exploit for CVE-2023-36723, an arbitrary directory creation vulnerability in Windows Container Manager, enabling privilege…

Port Scanner with Docker & Prometheus + Grafana integration. A tool for network auditing with multithreading support and real-time monitoring.

Proof-of-concept for Docker Desktop for Windows privilege escalation (CVE-2020-11492). Exploits named pipe impersonation to achieve SYSTEM-level…

Policy-driven, layered isolation and containment

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

A collection of awesome security hardening guides, tools and other resources

Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.

Your agent is a security risk, so treat it like one. yoloAI does AI agent sandboxing right.

Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…