
grapheneX
Automated System Hardening Framework

Automated System Hardening Framework

Linux Runtime Security and Forensics using eBPF

CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation

Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine,…

eBPF-based runtime detector for container breakout vulnerabilities in runc and Docker, monitoring syscalls and Docker daemon calls to detect…

Trust & Safety tools for working together to fight digital harms.

Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities

Docker-based lab demonstrating CVE-2019-15107, the Webmin unauthenticated RCE, covering deployment, exploitation, detection, and remediation.

:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

eBPF-based Linux security monitor and threat hunter providing chronologically ordered, container-aware events with on-host correlation for incident…

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

OWASP Honeypot, Automated Deception Framework.

eBPF-driven security tool for locking and auditing Linux machines. Restricts kernel features, blocks fileless execution, protects memory, and hardens…

the ps utility, with an eBPF twist and container context

Making containers more secure with eBPF and Linux Security Modules (LSM)