

Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

Automated SSH-based scanner and patcher for Linux kernel LPE vulnerabilities CVE-2026-43284 and CVE-2026-43500, with multi-host discovery, privilege…

Linux kernel module implementing a zero-configuration, OTP-based firewall for IoT devices. Transparently authenticates network traffic using a…

3 linux kernel bugs chains to do secure comm app using side channel to establish key and establish covert channe;

Proof-of-concept exploit for CVE-2019-11477, demonstrating a denial-of-service attack against Linux kernel TCP SACK panic via crafted netfilter…

Reference analysis of a Linux kernel Open vSwitch memory-corruption vulnerability, covering root cause, impact, detection commands, and mitigation…

Proof-of-concept exploit for CVE-2025-38501 that remotely exhausts KSMBD SMB server connection limits via incomplete TCP handshakes, enabling…

FIPS 140-3 compliant VPN kernel module and user tool, drop-in replacement for WireGuard with AES-256-GCM, SHA2-256, and SECP256R1 cryptography for…

High-speed packet processing framework

Automated Network Security with Rust: Detecting and Blocking Port Scanners

Kernel-level security & attack response for Linux servers.

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

ksmbd CVEs: CVE-2026-31717, CVE-2026-68083

DNXFIREWALL® and DAD'S NEXT-GEN FIREWALL™, a C/CPython hybrid next generation firewall built on top of Linux and bound to kernel/ netfilter hooks for…

Automated scanner and patch helper for CVE-2026-31431, detecting vulnerable Linux hosts via SSH, verifying kernel versions, and applying kernel…

Functional Network Framework for Multi-Core Architectures

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…