Add kspp-recommendations/kspp-sysctl.txt
authorAlexander Popov <alex.popov@linux.com>
Tue, 17 Oct 2023 20:34:14 +0000 (23:34 +0300)
committerAlexander Popov <alex.popov@linux.com>
Tue, 17 Oct 2023 20:34:14 +0000 (23:34 +0300)
kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt [new file with mode: 0644]

diff --git a/kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt b/kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt
new file mode 100644 (file)
index 0000000..9f99c6c
--- /dev/null
@@ -0,0 +1,18 @@
+kernel.printk = 3      4       1       7
+kernel.kptr_restrict = 2
+kernel.dmesg_restrict = 1
+kernel.perf_event_paranoid = 3
+kernel.kexec_load_disabled = 1
+kernel.randomize_va_space = 2
+kernel.yama.ptrace_scope = 3
+user.max_user_namespaces = 0
+dev.tty.ldisc_autoload = 0
+dev.tty.legacy_tiocsti = 0
+kernel.unprivileged_bpf_disabled = 1
+net.core.bpf_jit_harden = 2
+vm.unprivileged_userfaultfd = 0
+fs.protected_symlinks = 1
+fs.protected_hardlinks = 1
+fs.protected_fifos = 2
+fs.protected_regular = 2
+fs.suid_dumpable = 0