
kata-containers
Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

eBPF-based Security Observability and Runtime Enforcement

Linux Runtime Security and Forensics using eBPF

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

eBPF-based Linux security monitor and threat hunter providing chronologically ordered, container-aware events with on-host correlation for incident…

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

ClamAV antivirus scanning for Node.js — scan file uploads with a single function call. Zero dependencies. Typed Symbol verdicts. Local or…

OWASP Honeypot, Automated Deception Framework.

A Linux Host-based Intrusion Detection System based on eBPF.

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

the ps utility, with an eBPF twist and container context

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

Making containers more secure with eBPF and Linux Security Modules (LSM)

eBPF-driven security tool for locking and auditing Linux machines. Restricts kernel features, blocks fileless execution, protects memory, and hardens…

Qubes containerization on Windows