Fast zero-copy communication mechanism between kernel and user space in FreeBSD.
Automatic/transparent sandboxing of C/C++ code and dynamic shared objects via capsicum
Verify status of common security features in a running FreeBSD machine.
A MAC (Mandatory Access Control) module for FreeBSD that identifies executables based on their hash digest, and objects based on their st_dev/i_num. It supports transparent sandboxing at single process level.