/etc/sysctl.d
NameSizeModeActions
10-console-messages.conf770644editdlrm
10-ipv6-privacy.conf4900644editdlrm
10-kernel-hardening.conf7260644editdlrm
10-link-restrictions.conf2570644editdlrm
10-magic-sysrq.conf11840644editdlrm
10-network-security.conf1580644editdlrm
10-ptrace.conf12920644editdlrm
10-zeropage.conf5060644editdlrm
99-cloudimg-ipv6.conf1850644editdlrm
99-sysctl.conf23510644editdlrm
README.sysctl7920644editdlrm
Edit: /etc/sysctl.d/10-kernel-hardening.conf (726B)
# These settings are specific to hardening the kernel itself from attack # from userspace, rather than protecting userspace from other malicious # userspace things. # # # When an attacker is trying to exploit the local kernel, it is often # helpful to be able to examine where in memory the kernel, modules, # and data structures live. As such, kernel addresses should be treated # as sensitive information. # # Many files and interfaces contain these addresses (e.g. /proc/kallsyms, # /proc/modules, etc), and this setting can censor the addresses. A value # of "0" allows all users to see the kernel addresses. A value of "1" # limits visibility to the root user, and "2" blocks even the root user. kernel.kptr_restrict = 1