Skip to content

Childflow

Offensive & Pentesting

A per‑command‑tree network sandbox for Linux that isolates DNS, hosts, proxy, policy, and capture controls to a single command and its children

Rust Latest 0.8.1 · 2mo ago Security brief →

Features

  • Isolates one command tree in its own network namespace
  • Forces custom DNS resolution, /etc/hosts overrides, and proxy usage regardless of environment variables
  • Applies allow/deny CIDR policies and default‑deny rules to outbound traffic
  • Captures only the target tree’s traffic as PCAPNG or structured flow logs
  • Supports reusable TOML profiles for consistent sandbox configurations

Recent releases

View all 8 releases →
No immediate action
0.8.1 Breaking risk

maintainability

Review required
0.8.0 New feature
Auth RBAC

Observability + Policy + Profiles

Review required
0.7.0 New feature
Auth RBAC RCE / SSRF

Rootless sandbox + profiles + logs

No immediate action
0.6.0 New feature

Structured flow logging

Config change
0.5.0 New feature
RBAC Breaking upgrade

Outbound policy engine

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
9
Forks
0
Languages
Rust Shell Python

Install & Platforms

Install via
cargo
Platforms
linux

Beta — feedback welcome: [email protected]