There are 11 repositories under runtime-security topic.
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Cloud Native Runtime Security
Linux Runtime Security and Forensics using eBPF
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS
Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)
Deep Linux runtime visibility meets Wireshark
ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits
🐝 BPFBox 📦 Exploring process confinement in eBPF
Protect your Cloud Native Applications running on Kubernetes from malicious attacks with pre-registered source code, pre-registered runtime processes monitoring, automated actions based on configure-actions, analytics, alerting and also sharing detections with community. Maybe save from Ransomware. Shift-Left your threat detection. Shift Right threat elimination.
Community curated list of System and Network policy templates for the KubeArmor and Cilium
Kubernetes offensive framework built in eBPF
eBPF security monitoring agent based on Aya
PyRASP is a Runtime Application Self Protection package for Python-based Web Servers (Flask, FastAPI and Django), Serverless Functions (AWS Lambda, Azure and Google Cloud Functions) and MCP Servers (FastMCP)
Linux based vulnerabilities (CVE) exploit detection through runtime security using Falco/Osquery/Yara/Sigma
Ansible playbooks to provision firecracker VMs and run Falco kernel tests
Jibril: A performant and low impact Linux runtime security tool agent.
A Minecraft client injection platform with in-environment JVM object resolution against obfuscation.
Dralyxor: Advanced C++ header-only library for robust string obfuscation, shielding binaries from static/dynamic analysis. Uses a consteval micro-program engine with variable NOPs. Runtime anti-debug/tamper checks (canaries, content checksums) plus RAII "just-in-time" decryption ensure secure, minimal memory exposure of plain-text data.
eBPF-based runtime agent for Endpoint Detection and Response for Linux based operating systems.
Keep your Kubernetes workloads in tune — secure and functional.
Jibril releases (automated).
Trust and compliance engine for AI agents — OSS CLI, SDK, and audit tools.
POC developed while writing the paper "A weakness in eBPF-based runtime security applications"
Gardener extension controller to deploy Falco into shoot clusters.
CentOS based Docker Security Architecture
In this AKS-focused workshop, you will work with Calico Cloud to learn how to implement runtime security to protect containers in your Kubernetes cluster from known and zero-day threats based container and network attacks running on Microsoft AKS.
POC Repo for Implementing Runtime Security fo a Kubernetes Cluster.
Github, Linear related MCP Server exposing a nuanced MCP Server Vulnerability at runtime
Comprehensive real-time security platform for Kubernetes-based cloud-native applications. Features runtime security monitoring, vulnerability scanning, compliance automation, and policy enforcement using OPA, Falco, Trivy, and Aqua Security.
Bugsmirror MASST (Mobile Application Security Suite and Tools) is a comprehensive platform for end-to-end mobile application security. It offers threat detection tools for static, runtime, dynamic API testing and red teaming; robust app shielding solution for threat mitigation; threat visibility dashboard; & AI powered insight in a single platform.
client and types for garnet platform