
sandbox-runtime
A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Provides supplemental files and Debian package sources for a specialized Linux distro focused on malware analysis, reverse engineering, and digital…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Boot and manage virtual iPhones on Apple Silicon with firmware patching, jailbreak variants, and security research features for iOS testing and…

Main UserLAnd Repository

CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction

PoC and Docker lab for CVE-2026-49869, an unauthenticated RCE in Kestra OSS via an AuthenticationFilter path bypass that allows flow creation and…

Python proof-of-concept for CVE-2026-34990 in OpenPrinting CUPS, coercing cupsd to leak a Local auth token and overwrite root files via a file://…

The patching of Android kernel and Android system

Minimal PoC for CVE-2026-34990: local privilege escalation in CUPS <= 2.4.16 that leaks cupsd's Local auth token and writes a NOPASSWD sudoers…

Linux application sandboxing and distribution framework

Easily create full virtual machines that are sandboxed for development or computer use models.

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

Pre-Built Vulnerable Environments Based on Docker-Compose

Composable research-contract and YAML-recipe framework for agent-operated security experiments on disposable compute

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…

C library implementing FrodoKEM, a post-quantum key encapsulation mechanism based on the Learning with Errors problem, with variants for AES and…