
bombini
eBPF Security Monitoring and Sandboxing Agent Based on Aya

eBPF Security Monitoring and Sandboxing Agent Based on Aya

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Automated System Hardening Framework

A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

eBPF-driven security tool for locking and auditing Linux machines. Restricts kernel features, blocks fileless execution, protects memory, and hardens…

Trust & Safety tools for working together to fight digital harms.

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

BPF LSM blocker for CVE-2026-31431 (Copy Fail) - zero-reboot remediation for OpenShift 4

Research and detection guidance for CVE-2026-31431, an io_uring-based bypass of syscall monitoring. Provides detection rules for Tetragon, Falco, and…

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation

Zero-trust sandbox for AI agents with kernel-level filesystem jail, transparent network proxy, and YAML-based policy engine to intercept and control…