A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security. It utilizes Linux namespace subsystem, resource limits, and the seccomp-bpf syscall filters of the Linux kernel.

Features

  • Isolate networking services (e.g. web, time, DNS), by isolating them from the rest of the OS
  • Host computer security challenges (so-called CTFs)
  • Contains invasive syscall-level OS fuzzers
  • Offers three distinct operational modes
  • Utilizes kafel seccomp-bpf configuration language for flexible syscall policy definitions
  • Uses expressive, ProtoBuf-based configuration file

Project Samples

Project Activity

See All Activity >

Categories

Security

License

Apache License V2.0

Follow nsjail

nsjail Web Site

You Might Also Like
MongoDB Atlas runs apps anywhere Icon
MongoDB Atlas runs apps anywhere

Deploy in 115+ regions with the modern database for every enterprise.

MongoDB Atlas gives you the freedom to build and run modern applications anywhere—across AWS, Azure, and Google Cloud. With global availability in over 115 regions, Atlas lets you deploy close to your users, meet compliance needs, and scale with confidence across any geography.
Start Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of nsjail!

Additional Project Details

Operating Systems

Linux, Mac, Windows

Programming Language

C++

Related Categories

C++ Security Software

Registered

2024-06-20