
chimera
Sandbox untrusted code with safe access to the host.

Sandbox untrusted code with safe access to the host.

An embeddable, portable, branchable virtual machine to safely run Agents locally.

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Macro-header for compile-time C polymorphic obfuscation (tcc, win x86/x64)

The patching of Android kernel and Android system

Docker-based sandbox for coding agents with isolated environments, preinstalled agent tooling, service control, and workspace bootstrap for secure…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Boot and manage virtual iPhones on Apple Silicon with firmware patching, jailbreak variants, and security research features for iOS testing and…

Main UserLAnd Repository

A security-focused library OS supporting kernel- and user-mode execution

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

🪅 Windows & Linux userspace emulator

Manages the core lifecycle of Qubes OS domains via a Python admin API, handling secure compartmentalization with Xen and exposing an event system for…

Linux namespaces and seccomp-bpf sandbox