Landlook runs your application in a restricted Landlock sandbox and intercepts kernel audit events in real-time. When an action is blocked, it appears in an interactive Terminal UI, where you can instantly approve legitimate behaviors (file access, network calls, etc). Then you iteratively restart the app with the updated profile, discovering deeper dependencies until you’ve built a perfect, least-privilege security policy.
cnaize•1h ago