nsjail

Process isolator

A lightweight process isolation tool for Linux that provides isolated environments for network services and local processes.

A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.

GitHub

3k stars
88 watching
276 forks
Language: C++
last commit: almost 2 years ago
Linked from 1 awesome list

chrootlinuxlinux-namespacesprocess-isolationseccomp-bpf-policiessecurity

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
netblue30/firejailA security tool designed to restrict the environment of potentially untrusted applications on Linux systems.5,855
google/gvisorAn application kernel that provides isolation between running applications and the host operating system15,931
shamedgh/confineGenerates Seccomp profiles to reduce Linux kernel vulnerabilities in containers62
cohdjn/cisecurityAutomates Linux hardening to conform to Center for Internet Security Benchmark standards9
google/oss-fuzzAn automated testing framework that uses random data to find errors in software10,671
containers/bubblewrapSandboxing tool to provide isolation and security for unprivileged users4,010
google/sanitizersMaintains documentation and helper code for a set of sanitizers to detect and prevent common programming errors.11,610
trimstray/the-practical-linux-hardening-guideA comprehensive guide to creating secure Linux production systems using industry standards and best practices9,956
opennhp/opennhpA Zero Trust protocol that leverages resource-hiding and encryption to safeguard servers and data from attackers13,520
gchq/cyberchefA web-based tool for manipulating data through various encoding, encryption, compression, and analysis operations29,563
dominicbreuker/pspyA tool to monitor Linux processes without root permissions5,005
anchore/syftGenerates detailed visibility into software packages and dependencies to manage vulnerabilities and license compliance.6,371
google/syzkallerAn unsupervised coverage-guided kernel fuzzer5,428
evilsocket/opensnitchAn interactive application firewall that allows users to filter and manage network connections on GNU/Linux systems.11,023
brexhq/substationA toolkit for routing, normalizing, and enriching security event logs across the cloud332