How to actually work with SELinux instead of disabling it — reading denials, using audit2allow responsibly, understanding contexts and booleans, and keeping the one mechanism designed to contain a compromised service enabled.
Selinux
-
SELinux in Practice (Not 'Disable It') -
Linux Hardening Checklist A practical Linux hardening checklist covering CIS benchmark controls, auditd syscall monitoring, AppArmor and SELinux mandatory access control, kernel parameter tuning, and automated scoring with Lynis.