
kAFL
A fuzzer for full VM kernel/driver targets

A fuzzer for full VM kernel/driver targets

AArch64 fuzzer based on the Apple Silicon hypervisor


Source code of a multiple series of tutorials about the hypervisor. Available at: https://rayanfam.com/tutorials

A secure low code deception runtime framework, leveraging AI for System Virtualization.

A collection of links related to VMware escape exploits

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

Lightweight fuzzing of a memory snapshot using KVM

A Linux framework to enable userspace-defined "Virtual" PCIe card shims to enable in-host PCIe card driver development.

A QEMU/KVM-based USB fuzzing framework that finds device-driver bugs via reproducible VM execution, multiprocessing, and XML testcase generation.

Run untrusted AI code safely, fast

ArmourBird CSF - Container Security Framework

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

The fastest LoongArch sandbox

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…