
firejail
Linux namespaces and seccomp-bpf sandbox

Linux namespaces and seccomp-bpf sandbox

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

Manages the core lifecycle of Qubes OS domains via a Python admin API, handling secure compartmentalization with Xen and exposing an event system for…

Minimal unikernel firewall for QubesOS that filters network traffic, implements NAT, and communicates via Qubes DB and qrexec.

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

Secure code execution

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

MDE/MDI Defender setup for Ludus

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

eBPF LSM program that blocks AF_ALG socket creation to mitigate CVE-2026-31431, with userspace daemon logging denied attempts via ring buffer.

Rust exploit PoC for Linux kernel LPE CVE-2026-31431 (AF_ALG page-cache write) plus eBPF runtime defense blocking AF_ALG socket creation via LSM or…

eBPF-based workaround for CVE-2026-31431 (Copy.Fail) that filters or kills AF_ALG socket creation to prevent local privilege escalation and container…

Open source log management platform for centralized log aggregation, real-time analysis, and security event monitoring with customizable dashboards…

A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analysis.

A tool to recover from ESXiArgs ransomware

Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.

An example sandbox using AppContainer (Windows 8+)

Windows Process Lockdown Tool using Job Objects