
kata-containers
Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

An embeddable, portable, branchable virtual machine to safely run Agents locally.

Gentoo overlay for security tools as well as the heart of the Pentoo Livecd

A durable process per agent, with memory that survives restarts

A security-focused library OS supporting kernel- and user-mode execution

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

Policy-driven, layered isolation and containment

Run Windows inside a Docker container with KVM acceleration, automatic installation, and customizable resources. Supports multiple Windows versions,…

Let your AI go full send. Your home directory stays home.

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

An ArchLinux based distribution for penetration testers and security researchers.

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

Shared Go SDK defining a standard capability interface for security scanners, with multi-format finding output (terminal, JSON, NDJSON, Markdown,…

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…