
vpod
Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

RISC-V emulator in Rust that boots Linux with JIT on ARM64/x86_64 and Sv39 virtual memory

A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

iPhone 11 emulated on QEMU

Composable research-contract and YAML-recipe framework for agent-operated security experiments on disposable compute

Run any command inside a restricted filesystem view on Linux

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

Linux application sandboxing and distribution framework

Main UserLAnd Repository

Source code of a multiple series of tutorials about the hypervisor. Available at: https://rayanfam.com/tutorials

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

Easily create full virtual machines that are sandboxed for development or computer use models.

Self-hosted threat intelligence platform — feed aggregation, AI triage, MITRE ATT&CK coverage, and Sentinel-integrated detection engineering. Runs…

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

PoC and Docker lab for CVE-2026-49869, an unauthenticated RCE in Kestra OSS via an AuthenticationFilter path bypass that allows flow creation and…