
Cordon
Run any command inside a restricted filesystem view on Linux

Automate the creation of a lab environment complete with security tooling and logging best practices

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Microsoft's curated repository of secure boot objects (KeK, Db, Dbx) for firmware and runtime, enabling transparent revocation updates and…

Seccomp-based mitigation for CVE-2026-31431, a Linux kernel LPE. Blocks AF_ALG socket via PAM module and standalone wrapper, with auto-detection of…

Here comes the paintrain!

Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754

Linux application sandboxing and distribution framework

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

A Microservices-based framework for the study of Network Security and Penetration Test techniques

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

GoTEE - example application

HvLoader.efi is an EFI application for loading an external hypervisor loader

Main UserLAnd Repository