

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…


Example demonstrating a Go-based trusted execution environment on ARM TrustZone and RISC-V, running concurrent unikernels as Trusted OS, Trusted…

Lord Of Active Directory - automatic vulnerable active directory on AWS

A fuzzer for full VM kernel/driver targets

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

Reference analysis of a Linux kernel Open vSwitch memory-corruption vulnerability, covering root cause, impact, detection commands, and mitigation…

Virtual machines manipulation framework

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Minimal unikernel firewall for QubesOS that filters network traffic, implements NAT, and communicates via Qubes DB and qrexec.

kali-linux-docker


Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Easily create full virtual machines that are sandboxed for development or computer use models.