
Zapscape
PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

Go Trusted Execution Environment (TEE)

Lord Of Active Directory - automatic vulnerable active directory on AWS

Firecracker made simple. Spin up secure microVMs in milliseconds, from install to interactive shell in one command.

Script to install prerequisites for deploying GOAD on Ubuntu Linux 22.04

Virtual machines manipulation framework

ArmourBird CSF - Container Security Framework

MDE/MDI Defender setup for Ludus

A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

The fastest LoongArch sandbox

GoTEE - example application

Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability.

Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

eBPF LSM program that blocks AF_ALG socket creation to mitigate CVE-2026-31431, with userspace daemon logging denied attempts via ring buffer.

iPhone 11 emulated on QEMU

Run any command inside a restricted filesystem view on Linux

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Pre-Built Vulnerable Environments Based on Docker-Compose