seccomp-tools
Installation
SKILL.md
seccomp-tools
Sandbox policy visibility for pwn and Linux-reversing work.
When to use seccomp-tools
Use seccomp-tools when you need to:
- dump a process or challenge binary's seccomp filter
- disassemble BPF policy logic into something readable
- confirm which syscalls are allowed, trapped, or killed
- adapt shellcode, ROP, or post-exploitation plans to the sandbox
Quick Start
# Dump seccomp filter from a local binary under execution
seccomp-tools dump ./chall