Automatic systemd service hardening guided by strace profiling
copied from cf-post-staging / shhSystemd Hardening Helper (SHH) can generate an optimal set of hardening options for systemd services. It profiles service behavior using strace and automatically generates appropriate systemd security options, enabling security hardening without breaking services due to overly restrictive sandboxing.