Linux namespaces and seccomp-bpf sandbox
一个Android通用svc跟踪以及hook方案——Frida-Seccomp
OCI hook to trace syscalls and generate a seccomp profile
Seccomp + Signal Intercept SVC
Frida-Sigaction-Seccomp实现对Android APP系统调用的拦截
一个基于ptrace-seccomp简单的重定向openat的demo
Sandstorm is a self-hostable web productivity suite. It's implemented as a security-hardened web app package manager.
Simple Linux seccomp rules without writing any code
Simplifying Seccomp enforcement in containerized or non-containerized apps
Go library for installing a seccomp BPF system call filter.
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
vArmor is a cloud native container sandbox system based on AppArmor/BPF/Seccomp. It also includes multiple built-in protection rules that are ready to use out of the box.