 jaandJunie
|
ccdaf95f15
|
docs(security): add AppArmor, systemd sandboxing, Falco, YARA, cosign, OIDC, Ansible integration
Complete hardening workflow now covers all key technical concepts:
- AppArmor/SELinux status, systemd sandboxing audit
- Semgrep SAST, YARA malware patterns, Nuclei network scan
- Cosign artifact verification, SHA256 package verification
- Falco/eBPF runtime monitoring, Volatility 3 memory forensics
- OIDC/GAT token best practices
- Ansible integration per .clinerules/workstation.md
Co-authored-by: Junie <junie@jetbrains.com>
|
2026-03-24 04:35:50 +01:00 |
|
 jaandJunie
|
e0c2997ee4
|
docs(security): add workstation hardening workflow for Arch Linux
Daily/weekly/monthly security checks covering systemd health,
network C2 detection, package audit, SBOM scanning, Unicode IOC
sweep, kernel hardening, and firewall status. References
supply-chain-security-2026-03.md for detailed threat context.
Co-authored-by: Junie <junie@jetbrains.com>
|
2026-03-24 04:34:31 +01:00 |
|