A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
-
Updated
Nov 4, 2024 - C++
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
Go library for installing a seccomp BPF system call filter.
🔒 download, verify & run torbrowser in a sandbox
Merged to firejail; Find syscalls of executables for seccomp-bpf sandbox policies.
Add a description, image, and links to the seccomp-bpf-policies topic page so that developers can more easily learn about it.
To associate your repository with the seccomp-bpf-policies topic, visit your repo's landing page and select "manage topics."