{"enrichment":{"faq":[{"a":"kernel-security teaches SELinux policy writing for service confinement, including how to author policies that restrict process capabilities and file access. The skill covers practical policy development, audit2allow workflows for analyzing denials, and best practices for confining services within security domains to limit lateral movement and privilege escalation risks.","q":"What does kernel-security cover for SELinux policy writing?"},{"a":"kernel-security provides seccomp-bpf filter configuration guidance, including libseccomp tutorials and practical examples for sandboxing processes. You'll learn to define syscall whitelists, handle architecture differences, and deploy filters in containers and services to restrict the kernel attack surface by blocking unnecessary system calls.","q":"How do I write seccomp-bpf filters to sandbox process syscalls?"},{"a":"kernel-security covers KASLR, Intel CET (shadow stack and IBT), and ARM PAC/BTI branch protection mechanisms. The skill explains how to enable these mitigations, understand their bypass techniques, and configure them across different architectures to defend against code reuse and control-flow hijacking exploits.","q":"What kernel exploit mitigations does kernel-security teach?"},{"a":"kernel-security provides a kernel CVE triage checklist and impact assessment methodology. You'll learn to evaluate CVE severity, determine affected kernel versions and configurations, prioritize patching, and implement workarounds when patches aren't immediately available\u2014essential for maintaining kernel security posture in production environments.","q":"How should I triage kernel CVE impact and apply patches?"},{"a":"Yes, kernel-security covers AppArmor profile authoring as an alternative to SELinux for service confinement. The skill teaches how to write AppArmor policies, understand the differences between SELinux and AppArmor approaches, and deploy profiles to sandbox processes and restrict resource access in Linux security frameworks.","q":"Can kernel-security help with AppArmor profile development?"},{"a":"kernel-security includes KASAN and KMSAN coverage for detecting memory bugs in kernel builds. You'll learn to enable these sanitizers during kernel compilation, interpret detection output for uninitialized memory and use-after-free issues, and integrate them into kernel hardening and exploit mitigation strategies.","q":"Does kernel-security cover memory sanitizers like KASAN?"}],"shadow_tags":["mandatory-access-control","exploit-mitigation","memory-safety","cpu-hardening","syscall-filtering","vulnerability-assessment","process-confinement","pointer-authentication","kernel-instrumentation"],"summary_rewrite":"Master Linux kernel security mechanisms including SELinux and AppArmor policy authoring, seccomp-bpf sandboxing, and exploit mitigations like KASLR, Intel CET, and ARM PAC. Learn to triage kernel CVEs, configure memory sanitizers, and design container security boundaries."},"files":[{"bytes":6249,"path":"skills/security/kernel-security/SKILL.md","sha256":"e2c8d60f024cb70504837e2b753759691102b80a615aa6c4f776961e8572de07","url":"https://skillfed.io/files/mohitmishra786/low-level-dev-skills/kernel-security/c480df37/SKILL.md"}],"id":"mohitmishra786/low-level-dev-skills/kernel-security","links":{"html":"https://skillfed.io/mohitmishra786/low-level-dev-skills/kernel-security","md":"https://skillfed.io/mohitmishra786/low-level-dev-skills/kernel-security.md","repo":"https://github.com/mohitmishra786/low-level-dev-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":19,"language":"JavaScript","last_updated":"2026-06-27","license":"MIT","name":"kernel-security","publisher":"mohitmishra786","stars":148},"relations":{"similar":[{"id":"mohitmishra786/low-level-dev-skills/binary-hardening"},{"id":"mohitmishra786/low-level-dev-skills/containers-internals"},{"id":"hypnguyen1209/offensive-claude/exploit-development"},{"id":"yaklang/hack-skills/linux-security-bypass"},{"id":"hypnguyen1209/offensive-claude/windows-mitigations"},{"id":"AI-Shell-Team/aish/sosreport-analyzer"},{"id":"martinholovsky/claude-skills-generator/sandboxing"},{"id":"blacklanternsecurity/red-run/linux-kernel-exploits"},{"id":"JosiahSiegel/claude-plugin-marketplace/docker-platform-guide"},{"id":"yaklang/hack-skills/kernel-exploitation"}]},"slug":{"owner":"mohitmishra786","repo":"low-level-dev-skills","skill":"kernel-security"},"version":"c480df37"}
