by MiguelHzBz on 11/4/22, 7:52 AM with 7 comments
by teddyh on 11/5/22, 8:07 PM
kernel.core_uses_pid Block USB devices
kernel.ctrl-alt-del Disable access to dmesg for unprivileged users
kernel.dmesg_restrict Disable kexec to prevent kernel livepatching
kernel.kptr_restrict Restrict access to kernel logs
The official documentation for /proc/sys and sysctl settings is here: https://www.kernel.org/doc/html/latest/admin-guide/sysctl/in...The article seems to mostly exist to be a showcase for Falco, which apparently is some sort of file change security monitor.
by anderspitman on 11/5/22, 8:10 PM
[0]: https://www.kernel.org/doc/Documentation/ABI/testing/sysfs-f...