Provider-driven Windows x64 C++20 emulation library built on Unicorn: remote memory, recursive calls, import/syscall interception, overlays, and execution control.
-
Updated
Aug 11, 2026 - C++
Provider-driven Windows x64 C++20 emulation library built on Unicorn: remote memory, recursive calls, import/syscall interception, overlays, and execution control.
🛡️ Windows filesystem sandbox for AI agents — intercepts ntdll syscalls and redirects writes into a copy-on-write overlay. Agents run git/node/python freely while the real disk stays untouched. Child-process injection, whiteout deletes, glob policy, nested-sandbox blocking.
Tri-Workload Zero Trust evaluation sandbox for adversarial AI safety testing, featuring user-space syscall interception, default-deny egress, and out-of-band cryptographic WORM auditing.
To associate your repository with the syscall-interception topic, visit your repo's landing page and select "manage topics."