
Linux_hardening_and_security
Collection of Linux hardening scripts and security configurations for system auditing, access control, and defensive posture improvement. Includes…

Collection of Linux hardening scripts and security configurations for system auditing, access control, and defensive posture improvement. Includes…

A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel…

A lightweight eBPF program to monitor file creation and modification events on Linux. This tool leverages eBPF (Extended Berkeley Packet Filter) to…

Generic kernel live patch for the KVM/x86 shadow-MMU use-after-free (Zapscape, CVE-2026-64561)

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…

Detect and mitigate CVE-2026-31431 (Copy Fail) on Linux systems.

eBPF-based Security Observability and Runtime Enforcement

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能,…

Detects exposure to CVE-2026-31431 (Copy Fail) and optionally mitigates by disabling the vulnerable algif_aead kernel module, providing verdicts and…

Permanent mitigation scripts for CVE-2026-31431 (Copy Fail) on Ubuntu 24.04, blacklisting the vulnerable algif_aead kernel module and updating…

Use dropbear over wireguard.

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

BPF-LSM mitigation for CVE-2026-31431 (Copy Fail) — denies AF_ALG socket creation cluster-wide