
vpod
Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

Branchable computing by using a portable, lightweight, self-contained virtual machine

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…

Secure and fast microVMs for serverless computing.

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Low-level unprivileged sandboxing tool used by Flatpak and similar projects

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

A security-focused library OS supporting kernel- and user-mode execution

Offline and security-first tool for syncing and managing agent skills

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Policy-driven, layered isolation and containment

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…