
bpfjailer
eBPF LSM based Mandatory Access Control and jailer

eBPF LSM based Mandatory Access Control and jailer

Self-hosted SSH access gateway in Go with OIDC/LDAP auth, RBAC, MFA, session recording, audit export, encryption at rest, IP rules, and policy…

Cross-platform command-line tools for configuring WireGuard VPN tunnels, offering key generation, peer management, and quick interface setup via wg…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Automated Network Security with Rust: Detecting and Blocking Port Scanners

iptables-based stateful firewall with human-friendly configuration and optional QoS (FireQOS) for bandwidth management.

Web interface for the nftables firewall on Linux, written in Go. The apply undoes itself after 120 seconds unless you confirm it — you cannot lock…

Multi-hop proxy tool for pentesters enabling traffic routing through multiple nodes, SOCKS5/SSH tunneling, port forwarding, remote shell, and…

SQL powered operating system instrumentation, monitoring, and analytics.

The easiest, most secure way to use WireGuard and 2FA.