GrapheneOS / linux-hardened
Minimal supplement to upstream Kernel Self Protection Project changes. Features already provided by SELinux + Yama and archs other than multiarch arm64 / x86_64 aren't in scope. Only tags have stable history. Currently maintained at https://github.com/anthraxx/linux-hardened.
☆419Updated 2 years ago
Alternatives and similar repositories for linux-hardened:
Users that are interested in linux-hardened are comparing it to the libraries listed below
- Minimal supplement to upstream Kernel Self Protection Project changes. Features already provided by SELinux + Yama and archs other than m…☆607Updated last week
- Unofficial forward ports of the last publicly available grsecurity patch☆151Updated 6 years ago
- Qubes Security Pack☆504Updated 2 months ago
- PKGBUILDs to build SELinux enabled packages for Arch Linux☆157Updated this week
- HardenedBSD implements strong exploit mitigations and security hardening technologies on top of FreeBSD, with a direct focus on the nexus…☆388Updated this week
- Qubes component: antievilmaid☆147Updated 8 months ago
- The Qubes OS Project issue tracker☆565Updated last week
- A minimal Linux that runs as a coreboot or LinuxBoot ROM payload to provide a secure, flexible boot environment for laptops, workstations…☆1,466Updated this week
- Qubes component: core-admin☆133Updated this week
- Qubes documentation☆358Updated last week
- Qubes component: linux-kernel☆92Updated this week
- My tool for working with Intel Management Engine - RETIRED REPO (see coreboot for new upstream)☆157Updated 6 years ago
- The Qubes OS Project Official Website☆333Updated this week
- HardenedBSD stable repo. Installer images built from this repo: http://installer.hardenedbsd.org/☆132Updated 4 years ago
- Encrypted boot partition manager with UEFI Secure Boot support☆204Updated last year
- Linux Kernel Runtime Guard☆445Updated this week
- DEPRECATED TPM enabled GRUB2 Bootloader☆194Updated 3 years ago
- Check whether AMT is enabled and provisioned under Linux☆466Updated 7 years ago
- USBGuard is a software framework for implementing USB device authorization policies (what kind of USB devices are authorized) as well as …☆1,201Updated last week
- dracut the event driven initramfs infrastructure☆633Updated 2 weeks ago
- System76 Firmware Update Utility☆209Updated 3 weeks ago
- A utility like pkg-audit for Arch Linux. Based on Arch Security Team data.☆331Updated 9 months ago
- A Mirage firewall VM for QubesOS☆219Updated last month
- OZ: a sandboxing system targeting everyday workstation applications☆436Updated 7 years ago
- Scripts to slightly improve the security of the Linux boot process with UEFI Secure Boot and TPM support☆277Updated 2 years ago
- Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and gl…☆1,413Updated this week
- UEFI shim loader☆940Updated last week
- Fend off malware at Qubes VM startup☆74Updated 2 years ago
- Arch Linux Security Tracker☆126Updated 11 months ago
- zuluCrypt is a front end to cryptsetup and tcplay and it allows easy management of encrypted block devices☆533Updated last month