• Overview
  • Topics
    • 0day
    • 2FA
    • Amplification
    • Android
    • anecdote
    • Arduino
    • ARM
    • ASN
    • Autonomous System
    • BGP
    • Breach Monitoring
    • Bufferbloat
    • C
    • Censorship
    • Certificate
    • Cheatsheet
    • Code
    • CTF
    • CVE
    • Data Breach
    • Data Tools
    • Dataset
    • DDoS
    • Diagnostic Tools
    • diff
    • difftastic
    • Disk Encryption
    • Disposable Email
    • DKIM
    • DMARC
    • DNS
    • DNSSEC
    • Docker
    • Domain Rankings
    • Email
    • EXIF
    • Fedora
    • Game
    • Git
    • GPS
    • Hash
    • HTML
    • HTTP
    • humor
    • IANA
    • Icon
    • IETF RFC
    • Image
    • IP
    • IPv6
    • IXP
    • JSON
    • LaTeX
    • LUKS
    • Machine Learning
    • Malware
    • Map
    • Markdown
    • Movie
    • MTA-STS
    • Network
    • Network Testing
    • Networking
    • Paper Writing
    • Password
    • PCAP
    • Performance
    • PGP
    • Privacy
    • Protocols
    • Proxy
    • Python
    • QUIC
    • Regex
    • Reverse Engineering
    • RPKI
    • Rust
    • Search
    • Security
    • Security Research
    • Shell
    • Spam
    • SPF
    • SQL
    • TCP
    • technical-support
    • TeX
    • Threat Intelligence
    • Tips&Tricks
    • TLS
    • Tool
    • Tools
    • TPM2
    • Traceroute
    • Tutorial
    • Tutorials
    • Unicode
    • VPN
    • VS Code
    • Vulnerability
    • Windows
    • x86
  • Publications
  • Cloudflare Rule Linter

Generate SECCOMP Profiles for Containers

https://podman.io/blogs/2019/10/15/generate-seccomp-profiles.html

Docker | Tutorial

This blog post explains how to generate SECCOMP profiles for containers. This is possible using podman and eBPF filters. Custom SECCOMP profiles allow limiting the container to exactly those syscalls it needs.