#Seccomp
I just finished our #shmoocon talk on container security. Here's my seccomp bpf disassembler and diffing tool.

github.com/antitree/sec...
GitHub - antitree/seccomp-diff
Contribute to antitree/seccomp-diff development by creating an account on GitHub.
github.com
January 11, 2025 at 4:39 PM
Um salve pra seccomp q curtiu minha miku de crochê
October 13, 2024 at 7:12 PM
NsJail is a process isolation tool for Linux. It utilizes Linux namespace subsystem, resource limits, and the seccomp-bpf syscall filters of the Linux kernel. nsjail.dev
February 5, 2025 at 8:34 AM
XXXII SECComp nunca será a XXX SECComp
September 30, 2024 at 12:31 PM
Não vou mentir, achei esse cronograma da seccomp MUITO foda
September 29, 2024 at 4:47 PM
seccomp, however, is much worse. seccomp is fragile: i have had to downgrade musl on a few occasions in alpine because upgrading it broke everyone due to the seccomp policy included with containerd not being updated for newer syscalls.
April 10, 2026 at 1:47 AM
Deus abençoe a seccomp
September 30, 2024 at 5:47 PM
seccomp vai deixar saudades
October 8, 2024 at 3:03 PM
Why Seccomp Must Be Rechecked After Container Restore

https://linuxsecurity.com/news/cloud-security/seccomp-container-restore
September 23, 2026 at 7:00 AM
Sentindo falta de mais pesquisadores da academia nessa seccomp, parece q só tem empresa
September 27, 2024 at 6:50 PM
The irony that a k8s seccomp generation tool had an overly restritive seccomp policy _on itself_ causing it to crash and not generate seccomp profiles, is a fantastic example of the problem. Thanks.
March 13, 2026 at 9:44 PM
eBPF program which generates Seccomp profile
GitHub - rimvydascivilis/seccomp-profiler: eBPF program which generates Seccomp profile
eBPF program which generates Seccomp profile. Contribute to rimvydascivilis/seccomp-profiler development by creating an account on GitHub.
github.com
June 2, 2026 at 3:23 PM
Quick preview of my seccomp tool for containers that I'll be presenting tomorrow at #shmoocon
January 11, 2025 at 3:44 AM
Attack surface reduction via fine-grained SELinux policy rules and stripping out unused kernel features via kernel configuration goes a long way to protecting against vulnerabilities. There's also seccomp-bpf for various standard sandboxes but most of the attack surface reduction is via SELinux.
May 7, 2026 at 11:42 PM
> we can't drop the /dev/urandom fallback, it would break too many decade-old kernels

Ok. Fine. But we're getting a seccomp self-executing test that tests the fallback *and* itself and then another test that tests that the fallback runs only under test.

Also the fallback is slow.

go.dev/cl/608175
August 24, 2024 at 8:17 PM
Dia 2 de seccomp e eu to com a energia socada no meu cu ja
October 1, 2024 at 3:20 PM
Pra mim o alisson é o novo senhor seccomp
October 1, 2024 at 10:25 PM
June 23, 2026 at 10:49 AM
Minha geladeira fez uma tatuagem gigante da seccomp na costela
October 8, 2024 at 1:18 AM
Obrigada seccomp por me fazer PROGRAMAR de novo e ficar pensando em como resolver probleminhas bobos durante o banho
October 4, 2024 at 5:48 PM
alimentação do dia:
salgados da seccomp
October 4, 2024 at 5:26 PM
a subtractive sandbox starts from a position of ambient authority and voluntarily reduces that authority before executing code in the sandbox.

subtractive sandboxes are built with things like seccomp, openbsd's pledge and landlock.
April 10, 2026 at 1:42 AM
With the publishing of our 10th video on seccomp (www.youtube.com/watch?v=A8fU...), that's a wrap for the Datadog security labs series on #container #security fundamentals.

As well as the videos we've published 6 blogs (securitylabs.datadoghq.com/articles/?s=...) on this topic. Next k8s security!
Container Security Fundamentals - Seccomp
In this video we're looking at how to harden Docker containers by seccomp to filter syscalls that containers can make.To learn more, read our blog on Datadog...
www.youtube.com
December 5, 2023 at 3:56 PM