
securityonion
Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

Bypass llm guardrails by confusing it with fabricated tool output.

Secure and fast microVMs for serverless computing.

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

Offline and security-first tool for syncing and managing agent skills

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

Policy-driven, layered isolation and containment

Branchable computing by using a portable, lightweight, self-contained virtual machine

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Self-hosted threat intelligence platform — feed aggregation, AI triage, MITRE ATT&CK coverage, and Sentinel-integrated detection engineering. Runs…

Linux application sandboxing and distribution framework

A Microservices-based framework for the study of Network Security and Penetration Test techniques

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…