kernel.sysrq = 0
# Memory execution prevention
#kernel.exec-shield = 2
kernel.randomize_va_space=2
kernel.dmesg_restrict = 1
kernel.kptr_restrict = 2
#kernel.kexec_load_disabled = 1