
cyber-decoy
Experimental Decoy Broker

Experimental Decoy Broker

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Qubes containerization on Windows

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

An eBPF detection program for CVE-2022-0847

Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection,…

Softsensor Docker prototype

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

A Linux Host-based Intrusion Detection System based on eBPF.