
firejail
Linux namespaces and seccomp-bpf sandbox

Linux namespaces and seccomp-bpf sandbox

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Minimal unikernel firewall for QubesOS that filters network traffic, implements NAT, and communicates via Qubes DB and qrexec.

Manages the core lifecycle of Qubes OS domains via a Python admin API, handling secure compartmentalization with Xen and exposing an event system for…

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

Library for securely executing untrusted code in an AppArmor sandbox, primarily for Python; isolates execution with resource limits and configurable…

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

Build a Windows AD detection lab in Ludus with MDE/MDI pre-staging, Sysmon, WEF, and ADCS ESC1–ESC15 misconfigurations for testing detection and…

Open source log management platform for centralized log aggregation, real-time analysis, and security event monitoring with customizable dashboards…

A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analysis.

Recover VMware VMs affected by ESXiArgs ransomware by rebuilding VM metadata from unencrypted disks, generating new config files, and re-registering…

An example sandbox using AppContainer (Windows 8+)

Windows Process Lockdown Tool using Job Objects