Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
Linux Kernel 6.x / BPF POSIX 1003.1e Capabilities Landlock LSM (Linux 5.13+) Zero-Trust Sandbox

Linux Seccomp-BPF, Landlock & Linux Capabilities Sandbox Studio

An engineering studio and interactive policy synthesizer for Linux container isolation and kernel sandboxing. Generate raw Seccomp-BPF assembly filters, audit system call allowlists against container escape vectors, decompose root UID 0 into fine-grained Linux Capabilities, configure Landlock unprivileged filesystem rules, and synthesize production Docker, C (libseccomp), and Go configurations.

452 Syscalls
Linux x86_64 Kernel ABI
44 Blocked
Docker Default Denylist
14 / 41 Caps
Container Default Caps
RET_KILL_PROCESS
Default Seccomp Action
ENFORCED
PR_SET_NO_NEW_PRIVS

Interactive Seccomp-BPF Assembly Filter Synthesizer

Seccomp-BPF compiles a system call filter into classical BPF instructions executed by the kernel on every single syscall. Choose an isolation posture, select required syscall categories, and generate ready-to-compile C macro filters or Docker OCI JSON profiles.

PERMITTED SYSCALL FUNCTIONAL GROUPS

Generating BPF assembly...

POSIX 1003.1e Linux Capabilities Decomposition

Linux replaces the all-or-nothing root model by splitting privileges into 41 distinct capability bits. Click chips to toggle capability sets and analyze the resulting container attack surface.

Selected Capabilities & Risk Audit

Click preset buttons above or toggle individual chips to evaluate privilege escalation risk.

Landlock LSM: Unprivileged Filesystem Sandboxing (Linux 5.13+)

Unlike AppArmor or SELinux which require root privileges and complex policy files, Landlock allows any unprivileged application to sandbox its own filesystem access at runtime.

Top 5 Container Escape Vectors & Kernel Mitigations

Analysis of real-world container escapes and how Seccomp-BPF and Capability pruning prevent them.

Attack Vector Exploited Mechanism Required Privilege Definitive Mitigation
cgroups release_agent Escape Writes host executable script into cgroup release_agent and triggers empty cgroup notification. CAP_SYS_ADMIN + root mount access Drop CAP_SYS_ADMIN. Block mount and pivot_root via Seccomp.
Kernel Exploitation via eBPF Unprivileged eBPF verifier bugs or JIT spraying causing ring-0 arbitrary memory write. Unrestricted bpf() syscall Seccomp block bpf() syscall. Set kernel.unprivileged_bpf_disabled = 1.
userfaultfd Kernel Race Exploits Using userfaultfd to pause page faults and win kernel race conditions (e.g. Dirty COW variants). Unrestricted userfaultfd() Seccomp block userfaultfd(). Set vm.unprivileged_userfaultfd = 0.
ptrace Process Injection Attaching ptrace to host-namespaced processes or shared PID namespace containers. CAP_SYS_PTRACE + shared PID ns Drop CAP_SYS_PTRACE. Enforce isolated PID namespaces. Block ptrace in Seccomp.
Raw Socket Sniffing / Spoofing Crafting raw IP packets or sniffing ARP/DHCP traffic across the host bridge. CAP_NET_RAW Drop CAP_NET_RAW in container security context.

Production Sandboxing Blueprints & Profiles

Production-ready implementations in Docker OCI JSON, C (libseccomp), Go, and Systemd security directives.

Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement