Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
kernel-hardening-checker — A tool for checking the security hardening options of the Linux kernel | Kitploit
Tools/GitHubGitHub/a13xp0p0v/kernel-hardening-checker
Defensive ToolsVulnerability AnalysisConfiguration AuditingHardware Security
GitHuba13xp0p0v/kernel-hardening-checker

kernel-hardening-checker

A tool for checking the security hardening options of the Linux kernel

View Repository
2.1k1902210 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

kernel-hardening-checker

(formerly kconfig-hardened-check)

GitHub tag (latest by date) License: GPL v3
status-badge
functional test functional test coverage
engine unit-test unit-test coverage
static analysis package test

Motivation

There are plenty of security hardening options for the Linux kernel. A lot of them are not enabled by the major distros. We have to enable these options ourselves to make our systems more secure.

But nobody likes checking configs manually. So let the computers do their job!

kernel-hardening-checker (formerly kconfig-hardened-check) is a tool for checking the security hardening options of the Linux kernel.

License: GPL-3.0.

Repositories

  • At GitHub https://github.com/a13xp0p0v/kernel-hardening-checker
  • At Codeberg: https://codeberg.org/a13xp0p0v/kernel-hardening-checker (go there if something goes wrong with GitHub)
  • At SourceCraft: https://sourcecraft.dev/a13xp0p0v/kernel-hardening-checker

Features

kernel-hardening-checker supports checking:

  • Kconfig options (compile-time)
  • Kernel command line arguments (boot-time)
  • Sysctl parameters (runtime)

Supported architectures:

  • X86_64
  • X86_32
  • ARM64
  • ARM
  • RISC-V

The security hardening recommendations are based on:

  • [KSPP recommended settings][1]
  • [Direct feedback from the Linux kernel maintainers][23]
  • Kernel options disabled by [grsecurity][3] to cut attack surface
  • [CLIP OS kernel configuration][2]
  • [GrapheneOS][25] recommendations
  • [SECURITY_LOCKDOWN_LSM][5] patchset
  • [CIS Benchmark][27]

I also created the [Linux Kernel Defence Map][4], which is a graphical representation of the relationships between security hardening features and the corresponding vulnerability classes or exploitation techniques.

Attention!

Please note that changing the Linux kernel security parameters may also affect system performance and functionality of userspace software. Therefore, when setting these parameters, consider the threat model of your Linux-based information system and thoroughly test its typical workload.

Installation

There are multiple options:

  • You can install the package from this Git repository using pip:

    python3 -m pip install git+https://github.com/a13xp0p0v/kernel-hardening-checker
    

    If you encounter an error due to an externally managed environment, create a virtual environment using python3 -m venv.

  • You can install the kernel-hardening-checker package via the package manager on some GNU/Linux distributions. See https://repology.org/project/kernel-hardening-checker/versions

  • Alternatively, you can simply run ./bin/kernel-hardening-checker from the cloned repository without installation.

Usage

$ ./bin/kernel-hardening-checker -h
usage: kernel-hardening-checker [-h] [--version] [-m {verbose,json,show_ok,show_fail}]
                                [-a] [-c CONFIG] [-v KERNEL_VERSION] [-l CMDLINE]
                                [-s SYSCTL] [-p {X86_64,X86_32,ARM64,ARM,RISCV}]
                                [-g {X86_64,X86_32,ARM64,ARM,RISCV}]

A tool for checking the security hardening options of the Linux kernel

options:
  -h, --help            show this help message and exit
  --version             show program's version number and exit
  -m, --mode {verbose,json,show_ok,show_fail}
                        select a special output mode instead of the default one
  -a, --autodetect      autodetect and check the security hardening options of the
                        running kernel
  -c, --config CONFIG   check the security hardening options in a Kconfig file (also
                        supports *.gz files)
  -v, --kernel-version KERNEL_VERSION
                        extract the kernel version from a version file (such as
                        /proc/version) instead of using a Kconfig file
  -l, --cmdline CMDLINE
                        check the security hardening options in a kernel command line
                        file (such as /proc/cmdline)
  -s, --sysctl SYSCTL   check the security hardening options in a sysctl output file
                        (the result of "sudo sysctl -a > file")
  -p, --print {X86_64,X86_32,ARM64,ARM,RISCV}
                        print security hardening recommendations for the selected
                        architecture
  -g, --generate {X86_64,X86_32,ARM64,ARM,RISCV}
                        generate a Kconfig fragment containing the security hardening
                        options for the selected architecture

Output modes

  • no -m argument for the default output mode (see the example below)
  • -m verbose for printing additional info:
    • the configuration options without a corresponding check
    • the internals of complex checks with AND/OR, like this:
    -------------------------------------------------------------------------------------------
        <<< OR >>>                                                                             
    CONFIG_STRICT_DEVMEM                  |kconfig|cut_attack_surface|defconfig |     y      
    CONFIG_DEVMEM                         |kconfig|cut_attack_surface|   kspp   | is not set 
    -------------------------------------------------------------------------------------------
    
  • -m json for printing the results in JSON format (for combining kernel-hardening-checker with other tools)
  • -m show_ok for showing only successful checks
  • -m show_fail for showing only failed checks
Download Tool