
A tool for checking the security hardening options of the Linux kernel
(formerly kconfig-hardened-check)
There are plenty of security hardening options for the Linux kernel. A lot of them are not enabled by the major distros. We have to enable these options ourselves to make our systems more secure.
But nobody likes checking configs manually. So let the computers do their job!
kernel-hardening-checker (formerly kconfig-hardened-check) is a tool for checking the security hardening options of the Linux kernel.
License: GPL-3.0.
kernel-hardening-checker supports checking:
Supported architectures:
The security hardening recommendations are based on:
I also created the [Linux Kernel Defence Map][4], which is a graphical representation of the relationships between security hardening features and the corresponding vulnerability classes or exploitation techniques.
Please note that changing the Linux kernel security parameters may also affect system performance and functionality of userspace software. Therefore, when setting these parameters, consider the threat model of your Linux-based information system and thoroughly test its typical workload.
There are multiple options:
You can install the package from this Git repository using pip:
python3 -m pip install git+https://github.com/a13xp0p0v/kernel-hardening-checker
If you encounter an error due to an externally managed environment, create a virtual environment using python3 -m venv.
You can install the kernel-hardening-checker package via the package manager on some GNU/Linux distributions. See https://repology.org/project/kernel-hardening-checker/versions
Alternatively, you can simply run ./bin/kernel-hardening-checker from the cloned repository without installation.
$ ./bin/kernel-hardening-checker -h
usage: kernel-hardening-checker [-h] [--version] [-m {verbose,json,show_ok,show_fail}]
[-a] [-c CONFIG] [-v KERNEL_VERSION] [-l CMDLINE]
[-s SYSCTL] [-p {X86_64,X86_32,ARM64,ARM,RISCV}]
[-g {X86_64,X86_32,ARM64,ARM,RISCV}]
A tool for checking the security hardening options of the Linux kernel
options:
-h, --help show this help message and exit
--version show program's version number and exit
-m, --mode {verbose,json,show_ok,show_fail}
select a special output mode instead of the default one
-a, --autodetect autodetect and check the security hardening options of the
running kernel
-c, --config CONFIG check the security hardening options in a Kconfig file (also
supports *.gz files)
-v, --kernel-version KERNEL_VERSION
extract the kernel version from a version file (such as
/proc/version) instead of using a Kconfig file
-l, --cmdline CMDLINE
check the security hardening options in a kernel command line
file (such as /proc/cmdline)
-s, --sysctl SYSCTL check the security hardening options in a sysctl output file
(the result of "sudo sysctl -a > file")
-p, --print {X86_64,X86_32,ARM64,ARM,RISCV}
print security hardening recommendations for the selected
architecture
-g, --generate {X86_64,X86_32,ARM64,ARM,RISCV}
generate a Kconfig fragment containing the security hardening
options for the selected architecture
-m argument for the default output mode (see the example below)-m verbose for printing additional info:
-------------------------------------------------------------------------------------------
<<< OR >>>
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set
-------------------------------------------------------------------------------------------
-m json for printing the results in JSON format (for combining kernel-hardening-checker with other tools)-m show_ok for showing only successful checks-m show_fail for showing only failed checks