
minimal
CVE-hardened, minimal container images built from source with cosign signatures, SPDX SBOMs, and SLSA Level 3 provenance. Free, MIT-licensed, rebuilt…

CVE-hardened, minimal container images built from source with cosign signatures, SPDX SBOMs, and SLSA Level 3 provenance. Free, MIT-licensed, rebuilt…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

An easy to use and powerful chaos engineering experiment toolkit.(阿里巴巴开源的一款简单易用、功能强大的混沌实验注入工具)

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

eBPF-based Security Observability and Runtime Enforcement

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

System utility that identifies and restarts daemons using outdated libraries after package upgrades to maintain security. Supports containers and…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

VM-isolated sandbox for executing AI agent code securely. Supports MCP integration with Claude, OpenAI, Gemini, and other LLM tools. Features…

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

Multi-distribution Linux environment manager for Android using ADB/Shizuku integration. Run Arch, Kali, Debian, Ubuntu, and more in isolated proot…

eBPF-based stealth container that hides processes, sockets, eBPF objects, and audit logs from system monitoring tools, enabling covert…

Proof-of-concept exploit for CVE-2023-36723, an arbitrary directory creation vulnerability in Windows Container Manager, enabling privilege…

Cloud-native system telemetry pipeline that collects, processes, and exports system call events into a compact object-relational format for…

Proof-of-concept exploit for CVE-2020-10665 demonstrating local privilege escalation in Docker Desktop for Windows via hardlink-based arbitrary file…

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Proof-of-concept exploit for CVE-2022-39253 demonstrating Docker container escape via malicious Git repository build, enabling host file system read…

Proof-of-concept exploit for Kata Containers container escape (CVE-2020-2023) using mknod to modify guest filesystem and overwrite system binaries…