Firejail

C
C tier on Sandbox SoftwareScore 6.7 · #11 of 22
Android app
Not listed
Free plan
Yes
Runs on
Linux, self-hosted
firejail.wordpress.com
The Firejail homepage

Summary

Firejail is a Linux program that places untrusted applications in restricted environments. It uses Linux namespaces and seccomp-bpf to give sandboxed processes separate views of shared resources, including network, process, and mount tables. It can be used with servers, graphical applications, and login sessions, and runs on Linux computers with a 3.x kernel or newer. Its security controls include protocol filtering, noroot user namespaces, Linux capabilities, D-BUS filtering, and optional AppArmor or SELinux support. Mandatory Access Control can prevent more than 1,000 desktop applications from reaching passwords, encryption keys, and private data; more than 1,000 profiles are included by default. Firejail can create an isolated TCP/IP stack with its own routing table, firewall, and interfaces, and its nettrace feature can inspect traffic. It supports AppImage packages. Firetools adds a Qt5 graphical interface for launching and managing sandboxes, while FDNS offers a DNS-over-HTTPS proxy using non-logging providers. The free, self-hosted GPL v2 community project targets home users and Linux beginners rather than enterprise use.

Who it is for

It is aimed at home users and Linux beginners who want to restrict applications on Linux. It may also suit users seeking application profiles, network isolation, or a graphical companion interface.

What is good

  • Free community project with GPL v2 licensing.
  • Supports servers, graphical applications, and login sessions.
  • More than 1,000 application profiles are available by default.
  • Can create an isolated TCP/IP stack.
  • Firetools provides a Qt5 graphical interface.

What to know first

  • Requires Linux with a 3.x kernel or newer.
  • The project is focused on Linux desktops, not enterprise use.

Verdict

Firejail offers multiple controls for isolating Linux applications, including profiles and network restrictions. Its Linux focus and consumer-oriented scope make it a poor fit for users seeking an enterprise product or another operating system.

Firejail plans and pricing

All plans
Firejail community project Free Linux desktop focus · GPL v2 · no commercial goals firejail.wordpress.com · 30 Sept 2026

Compared on sandbox software

Free plan
Yesfirejail.wordpress.com
Isolation method
containerfirejail.wordpress.com
Persistent storage
Yesfirejail.wordpress.com
Network controls
Yesfirejail.wordpress.com
API or CLI access
Yesfirejail.wordpress.com
Deployment
self_hostedfirejail.wordpress.com

Facts

Sandboxing
Firejail is a SUID program that restricts untrusted applications using Linux namespaces and seccomp-bpf.firejail.wordpress.com · 30 Sept 2026
Kernel support
The software runs on Linux computers with a 3.x kernel version or newer.firejail.wordpress.com · 30 Sept 2026
Process isolation
Sandboxed processes receive private views of shared kernel resources including the network, process, and mount tables.firejail.wordpress.com · 30 Sept 2026
Application coverage
Firejail can sandbox servers, graphical applications, and user login sessions.firejail.wordpress.com · 30 Sept 2026
Security controls
Security filters include seccomp-bpf, communication protocol filtering, noroot user namespaces, Linux capabilities, D-BUS filtering, and optional AppArmor or SELinux support.firejail.wordpress.com · 30 Sept 2026
Access control
Mandatory Access Control blocks access to passwords, encryption keys, and private data for more than 1000 desktop applications.firejail.wordpress.com · 30 Sept 2026
Security profiles
More than 1000 application profiles are available by default in /etc/firejail.firejail.wordpress.com · 30 Sept 2026
Network isolation
Firejail can create an isolated TCP/IP stack with its own routing table, firewall, and interfaces.firejail.wordpress.com · 30 Sept 2026
Network monitoring
The software can inspect network traffic with its nettrace feature for analyzing and monitoring application behavior.firejail.wordpress.com · 30 Sept 2026
AppImage support
Firejail natively supports AppImage packages through the --appimage option.firejail.wordpress.com · 30 Sept 2026
GUI companion
Firetools is a Qt5 graphical interface providing a sandbox launcher, system-tray integration, editing, management, and statistics.firejail.wordpress.com · 30 Sept 2026
DNS companion
FDNS is a DNS-over-HTTPS proxy that uses DoH services from non-logging providers.firejail.wordpress.com · 30 Sept 2026
Desktop integration
Running sudo firecfg integrates Firejail with application menus and file-manager launches.firejail.wordpress.com · 30 Sept 2026
Target users
The project identifies home users and Linux beginners as its target market and describes Firejail as a consumer product rather than an enterprise product.firejail.wordpress.com · 30 Sept 2026
Support
The project directs support questions to its GitHub wiki and asks users to report security bugs by email.firejail.wordpress.com · 30 Sept 2026

Best Firejail alternatives

See all 20

Where it ranks on Everything Xiaomi

Is Firejail yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources