Slim(toolkit): Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
Seccomp GitHub Repositories
Explore popular GitHub repositories tagged “seccomp”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Sandstorm is a self-hostable web productivity suite. It's implemented as a security-hardened web app package manager. | Actively sponsored by our friends at TestMu AI
Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.
Provide powerful tools for seccomp analysis
The main libseccomp repository
A stupid game for learning about containers, capabilities, and syscalls.
Lightweight, container-free sandbox for running commands with network and filesystem restrictions
The Kubernetes Security Profiles Operator
vArmor is a cloud-native container hardening system that leverages AppArmor/BPF/Seccomp and NetworkProxy technologies to enforce access control from system calls to application protocols — protecting workloads including AI Agents.
Tool and framework for securely reading untrusted USB mass storage devices.
minT(oolkit): Mint awesome, secure and production ready containers just the way you need them! Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
The lightest AI sandbox. A process-based sandbox for Linux, no container, no VM, no privilege, no prompt injection
The libseccomp golang bindings repository
A set of curated exercises to help you prepare for the CKS exam
Container-free, deny-by-default sandbox for AI coding agents. Kernel-enforced filesystem, network, and syscall isolation for Linux and macOS
Library-Level eBPF Sandbox for Python (Linux & macOS): syscall-level control per module.
🔍 Function-level tracing tool for Seccomp profiling, with eBPF
Rust implementation of PRoot, a ptrace-based sandbox
Generate seccomp profiles from go binaries
This is a public archive. The code now lives in the mono-repo: https://github.com/rust-vmm/rust-vmm/
Simplifying Seccomp enforcement in containerized or non-containerized apps
Go library for installing a seccomp BPF system call filter.
Run AI coding agents in hardened container sandboxes.
Build custom Docker seccomp profiles for containers by finding syscalls it uses.
C reimplementation of seccomp-tools with advanced features
Process isolation for Linux using namespaces, resource limits, cgroups, landlock and seccomp.
Record process launches and files read and written by each process
BPF Processor for IDA Python
Docker Secure Computing Profile Generator
Control plane for system processes