> I'm not sure what security-misc exactly is
Inspired by Kernel Self Protection Project (KSPP) Implements most if not all recommended Linux kernel settings (sysctl) and kernel parameters by KSPP. https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project On top of that does other things. These are fully documented (or at least mentioned) in the readme: https://github.com/Whonix/security-misc Some changes may or may be more controversial. You tell me. As for kernel settings (sysctl) and kernel parameters by KSPP... Our files in https://github.com/Whonix/security-misc/tree/master/etc/default/grub.d and https://github.com/Whonix/security-misc/tree/master/etc/sysctl.d could be merged into hardening-runtime? Cheers, Patrick