A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security. It utilizes Linux namespace subsystem, resource limits, and the seccomp-bpf syscall filters of the Linux kernel.

Features

  • Isolate networking services (e.g. web, time, DNS), by isolating them from the rest of the OS
  • Host computer security challenges (so-called CTFs)
  • Contains invasive syscall-level OS fuzzers
  • Offers three distinct operational modes
  • Utilizes kafel seccomp-bpf configuration language for flexible syscall policy definitions
  • Uses expressive, ProtoBuf-based configuration file

Project Samples

Project Activity

See All Activity >

Categories

Security

License

Apache License V2.0

Follow nsjail

nsjail Web Site

Other Useful Business Software
Cut Cloud Costs with Google Compute Engine Icon
Cut Cloud Costs with Google Compute Engine

Save up to 91% with Spot VMs and get automatic sustained-use discounts. One free VM per month, plus $300 in credits.

Save on compute costs with Compute Engine. Reduce your batch jobs and workload bill 60-91% with Spot VMs. Compute Engine's committed use offers customers up to 70% savings through sustained use discounts. Plus, you get one free e2-micro VM monthly and $300 credit to start.
Try Compute Engine
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of nsjail!

Additional Project Details

Operating Systems

Linux, Mac, Windows

Programming Language

C++

Related Categories

C++ Security Software

Registered

2024-06-20