
webvm
Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Run Windows inside a Docker container with KVM acceleration, automatic installation, and customizable resources. Supports multiple Windows versions,…

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

Customizable Windows-based virtual machine distribution pre-packaged with offensive security tools for penetration testing and red teaming operations.

Linux namespaces and seccomp-bpf sandbox

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Linux application sandboxing and distribution framework

Automate the creation of a lab environment complete with security tooling and logging best practices

A security-focused library OS supporting kernel- and user-mode execution

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

Framework for compiling and executing Go applications on bare metal processors, enabling secure firmware development with reduced attack surface…

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

Course materials and hands-on labs for building a Rust-based fuzzing hypervisor using hardware-assisted virtualization on Intel/AMD, targeting UEFI…

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…