
tetragon
eBPF-based Security Observability and Runtime Enforcement

eBPF-based Security Observability and Runtime Enforcement

Linux Runtime Security and Forensics using eBPF

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

Making containers more secure with eBPF and Linux Security Modules (LSM)

eBPF-driven security tool for locking and auditing Linux machines. Restricts kernel features, blocks fileless execution, protects memory, and hardens…

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

eBPF-based Linux security monitor and threat hunter providing chronologically ordered, container-aware events with on-host correlation for incident…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

the ps utility, with an eBPF twist and container context

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine,…

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ClamAV antivirus scanning for Node.js — scan file uploads with a single function call. Zero dependencies. Typed Symbol verdicts. Local or…

OWASP Honeypot, Automated Deception Framework.

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine…