
firecracker
Secure and fast microVMs for serverless computing.

Secure and fast microVMs for serverless computing.

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Boot and manage virtual iPhones on Apple Silicon with firmware patching, jailbreak variants, and security research features for iOS testing and…

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

An ArchLinux based distribution for penetration testers and security researchers.

Customizable Windows-based virtual machine distribution pre-packaged with offensive security tools for penetration testing and red teaming operations.

Linux namespaces and seccomp-bpf sandbox

The patching of Android kernel and Android system

Low-level unprivileged sandboxing tool used by Flatpak and similar projects

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Automate the creation of a lab environment complete with security tooling and logging best practices

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

A security-focused library OS supporting kernel- and user-mode execution

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…