Home▸Cybersecurity▸Seccomp Syscall Filter Sandbox (2D)

Seccomp Syscall Filter Sandbox (2D)

Interactive 2D seccomp-BPF sandbox simulator: watch a process fire real syscalls (open, execve, ptrace, mount...) at a policy ring, set each syscall category to Allow, Trap-log or Kill, drag to pan and scroll to zoom, and see a hostile syscall burst either get contained or take the process down.

Cybersecurity2DAdvanced60 FPS📱 Mobile-adapted⇄ 3D version
2d-sandbox-technologies ↗ Open standalone

Every sandboxing technology — containers, WebAssembly runtimes, microVMs, hardened Linux services — ultimately relies on filtering which system calls a piece of code is allowed to make. This simulator renders that boundary in a flat top-down view: a process on the left continuously fires real syscalls (grouped into file, network, process, privilege, memory and device categories) at a ring of policy nodes. Set each category to Allow, Trap-log or Kill, dial the syscall rate, and fire an attack burst of genuinely dangerous calls (ptrace, mount, setuid, execve) to see whether your policy actually contains a real privilege-escalation attempt — or whether the process gets sacrificed by a kill-on-sight rule, exactly as SECCOMP_RET_KILL_PROCESS behaves on a real Linux host.

⚙ Under the hood

A flat, top-down seccomp-BPF sandbox: a process fires real syscalls at a ring of policy nodes while you set each syscall category to Allow, Trap-log or Kill, then launch an attack burst of privilege-escalation calls to see whether your policy actually contains it.

cybersecuritysandboxseccomplinux-kernelcontainerssyscalls

2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install

What did you find?

Add reproduction steps (optional)