
kata-containers
Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine,…

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Qubes containerization on Windows

Softsensor Docker prototype

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

OWASP Honeypot, Automated Deception Framework.

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine…

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection,…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

An eBPF detection program for CVE-2022-0847