Allow — reaches kernel Trap-log — denied & audited Kill — process terminated
drag to pan · scroll to zoom

Seccomp Syscall Filter Sandbox (2D)

Every sandboxing technology — containers, WebAssembly runtimes, microVMs, hardened Linux services — ultimately relies on filtering which system calls a piece of code is allowed to make. This simulator renders that boundary in a flat top-down view: a process on the left continuously fires real syscalls (grouped into file, network, process, privilege, memory and device categories) at a ring of policy nodes. Set each category to Allow, Trap-log or Kill, dial the syscall rate, and fire an attack burst of genuinely dangerous calls (ptrace, mount, setuid, execve) to see whether your policy actually contains a real privilege-escalation attempt — or whether the process gets sacrificed by a kill-on-sight rule, exactly as SECCOMP_RET_KILL_PROCESS behaves on a real Linux host.