Sandboxes, Seccomp, and Syscalls
Building Insecure and Incomplete Profiles Bypasses and Breakouts Measuring Scoring and Scaling with Seccompute I’ve been describing a common thread throughout these posts which is …
Sandboxes, Seccomp, and Syscalls
Building Insecure and Incomplete Profiles Bypasses and Breakouts Measuring Scoring and Scaling with Seccompute The other post, I’ve been mostly describing the operational burden of …
Sandboxes, Seccomp, and Syscalls
Building Insecure and Incomplete Profiles Bypasses and Breakouts Measuring Scoring and Scaling with Seccompute The idea behind seccomp profiles for a container is simple: your container …
Sandboxes, Seccomp, and Syscalls
Building Insecure and Incomplete Profiles Bypasses and Breakouts Measuring Scoring and Scaling with Seccompute It’s been a few weeks since I presented at BSidesSF. A talk called …
Seccompare.com quickly compares two container seccomp profiles and includes a handy syscall lookup table.
Are you interested in some practical guidance for applying custom seccomp profiles for a container? You …
seccomp-diff extracts the real seccomp filters straight from a running container Reverse engineering BPF taught me more about containers and syscalls than I expected seccomp good, seccomp at scale hard Ever wonder if …
This is a follow up from the Custom Seccomp profile post which went through some of the background information.
Speed up custom seccomp profile generation with Syscall2seccomp You can always manually track down the …
This post goes through building custom Docker seccomp profiles for your container. I’m not recommending you do this especially in enterprise environments, but I’m being charitable to the idea that system call …
One of Docker’s many updates this year was adding seccomp support. In short, seccomp/secomp-bpf is a way of filtering the system calls that you want to allow an application to make. It’s used for sandboxing …