A security-focused tool that implements an extremely restrictive network environment where nothing on the host can access the internet by default. All outbound internet access must be explicitly configured to use the Squid proxy, creating a "default deny" posture where applications cannot phone home without permission.
Expects/requires debian currently, using ip-tables -m owner to limit outgoing traffic to the dnsmasq, squid and chrony user.