
gvisor
Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

GoTEE - example application

Microsoft's curated repository of secure boot objects (KeK, Db, Dbx) for firmware and runtime, enabling transparent revocation updates and…

Linux application sandboxing and distribution framework

Main UserLAnd Repository

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Run any command inside a restricted filesystem view on Linux

Seccomp-based mitigation for CVE-2026-31431, a Linux kernel LPE. Blocks AF_ALG socket via PAM module and standalone wrapper, with auto-detection of…

A Microservices-based framework for the study of Network Security and Penetration Test techniques

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

HvLoader.efi is an EFI application for loading an external hypervisor loader

Automate the creation of a lab environment complete with security tooling and logging best practices

Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754

Here comes the paintrain!