
wasm2c-tableflip
wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

Run Windows inside a Docker container with KVM acceleration, automatic installation, and customizable resources. Supports multiple Windows versions,…

Secure and fast microVMs for serverless computing.

Pre-Built Vulnerable Environments Based on Docker-Compose

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Customizable Windows-based virtual machine distribution pre-packaged with offensive security tools for penetration testing and red teaming operations.

🛡️ Windows Hello™ style facial authentication for Linux

Linux namespaces and seccomp-bpf sandbox

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Linux application sandboxing and distribution framework

Automate the creation of a lab environment complete with security tooling and logging best practices

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…


An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.