lkrg
sysctl
Our great sponsors
lkrg | sysctl | |
---|---|---|
7 | 1 | |
397 | 190 | |
6.5% | - | |
7.9 | 3.2 | |
10 days ago | 10 months ago | |
C | ||
GNU General Public License v3.0 or later | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
lkrg
-
[Security] Questions about LKRG and Debian hardening-runtime
What's the difference between LKRG and hardening-runtimepackage?
- LKRG – Linux Kernel Runtime Guard
-
Tetragone: A Lesson in Security Fundamentals
Similar concerns affect LKRG. Check out the LKRG bypass article by Alexander Popov for the details.
-
windows kernel patch guard-like for linux ?
I'm not an expert, but I can think of two things related to the integrity of Linux kernel. Linux has the ability to mark itself tainted 1 if you, as example, load proprietary drivers. On the other hand, there's Linux Kernel Runtime Guard (LKRG) 2 that performs integrity check on Linux kernel and detects exploits.
-
Need help with template modification
I'll try to make this as succinct as possible. I use the Linux Kernel Runtime Guard with my kernel as a security measure, and I use xbps-src to compile the kernel myself.
- Linux Kernel Runtime Guard (LKRG)
- Linux Kernel Runtime Guard
sysctl
What are some alternatives?
ebpfkit - ebpfkit is a rootkit powered by eBPF
linux-network-performance-parameters - Learn where some of the network sysctl variables fit into the Linux/Kernel network flow. Translations: 🇷🇺
bouheki - bouheki is KRSI(eBPF+LSM) based Linux security auditing tool.
ansible-collection-hardening - This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL
linux-hardened - Minimal supplement to upstream Kernel Self Protection Project changes. Features already provided by SELinux + Yama and archs other than multiarch arm64 / x86_64 aren't in scope. Only tags have stable history. Shared IRC channel with KSPP: irc.libera.chat #linux-hardening
lynis - Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
zen-kernel - Zen Patched Kernel Sources
the-book-of-secret-knowledge - A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
fapolicyd - File Access Policy Daemon
How-To-Secure-A-Linux-Server-With-Ansible - Ansible playbooks of "How To Secure A Linux Server".
wiser - :racehorse: Extremely minimal vmm for linux written in C. Hopefully someday will spin linux-vm for you.
suhosin7 - Suhosin Extension for PHP 7.x