Maze Linux / Wiki

Security Reference

Maze Linux enables a layered security stack from first boot. Nothing needs to be turned on manually — every service listed here is active the moment you log in.


Security at a Glance

LayerToolVersionStatus
Mandatory access controlAppArmor3.1.7Enabled (kernel + service)
Host firewallfirewalld2.2.3Active — strict public zone
SSHsshd (hardened config)—Server off by default; root login disabled, 3 auth attempts
System audit logauditd—Active — hardened rule set
Network attack detectionMaze Guard—Autostarted on desktop
AntivirusClamAV + QLAM1.4.1On-access scanning + scheduled updates
Rootkit detectionrkhunter—Baseline database initialized
Security auditlynis—Installed
Kernel hardeningsysctl (custom)—Applied at boot

AppArmor

AppArmor 3.1.7 is a mandatory access control (MAC) system. It confines applications to only the files, capabilities, and system calls defined in their profile, limiting damage if an app is exploited. Maze ships with enforcement profiles for all major browsers and system services active from first boot.

How it's enabled:

Check status:

sudo aa-status

View active profiles:

sudo aa-status | grep enforce

AppArmor profiles shipped with packages are loaded automatically. You can write custom profiles in /etc/apparmor.d/.


firewalld

firewalld 2.2.3 manages the nftables rule set using a zone-based model. The default zone is public with a strict policy — all inbound connections are refused by default. Only traffic initiated by you is permitted outbound.

Check active rules:

sudo firewall-cmd --list-all

Add a port temporarily:

sudo firewall-cmd --add-port=8080/tcp

Add a port permanently:

sudo firewall-cmd --add-port=8080/tcp --permanent
sudo firewall-cmd --reload

GUI: firewall-config (install with sudo pacman -S firewall-config if needed).


auditd

The Linux Audit daemon records security-relevant system calls and file accesses into a structured audit log. Useful for forensics, compliance, and detecting unusual activity.

View recent audit events:

sudo ausearch -ts recent

Search for a specific file:

sudo ausearch -f /etc/passwd

Generate a report:

sudo aureport

Maze ships a hardened rule set covering sensitive paths (/etc/passwd, /etc/shadow, /etc/sudoers) and privilege escalation events. Audit rules live in /etc/audit/rules.d/.


Maze Guard

Maze Guard is Maze's own public Wi-Fi security monitor — a PyQt6 app backed by maze-guardd.service. It watches the network you are on for attacks: ARP spoofing and other MITM attempts, rogue gateways, suspicious traffic patterns. It integrates with firewalld to react.

systemctl status maze-guardd     # the daemon
maze-guardctl                    # command-line control

Maze Guard's GUI autostarts on the desktop.


ClamAV + QLAM

QLAM antivirus scanner

ClamAV is the antivirus engine; QLAM is the Maze-built GUI for it.

What is actually running: only clamav-freshclam is enabled, which keeps virus definitions up to date on a schedule. The on-access scanner (clamonacc / clamav-daemon) is not enabled — scanning is on demand, either from QLAM or with clamscan / clamdscan.

systemctl status clamav-freshclam   # definition updates
qlam                                # GUI scanner
clamscan -r ~/Downloads             # scan a folder from the shell

clamtk is also installed as a second, lighter GUI if you prefer it.


rkhunter

rkhunter checks for rootkits, backdoors, and local exploits by comparing file hashes and checking for known suspicious patterns.

First run (baseline):

sudo rkhunter --update
sudo rkhunter --propupd

Periodic check:

sudo rkhunter --check

Warnings should be investigated. Many are false positives — --propupd updates the baseline after you verify a change is legitimate.


lynis

lynis performs a comprehensive security audit of your system configuration and produces a hardening score with specific recommendations.

sudo lynis audit system

The report is saved to /var/log/lynis.log and /var/log/lynis-report.dat.


Hardened SSH

The SSH server (sshd) ships with secure defaults:

Switch to key-only authentication:

sudo sed -i 's/#PasswordAuthentication yes/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo systemctl restart sshd

The SSH server is not enabled at boot by default. Enable it only when needed:

sudo systemctl enable --now sshd

Disable again when not in use:

sudo systemctl disable --now sshd

Kernel Hardening (sysctl)

Maze applies kernel parameters at boot via /etc/sysctl.d/99-maze-hardening.conf. These are active from first boot — no action required.

Kernel restrictions

ParameterValueEffect
kernel.kptr_restrict2Hides kernel pointers from all users
kernel.dmesg_restrict1Only root can read dmesg
kernel.yama.ptrace_scope1Restricts ptrace to parent/child processes
kernel.unprivileged_bpf_disabled1Only root can load eBPF programs
net.core.bpf_jit_harden2Hardens the eBPF JIT compiler
kernel.kexec_load_disabled1Disables loading a new kernel at runtime
kernel.sysrq4Limits SysRq to safe keys only
fs.suid_dumpable0Disables core dumps from setuid programs
fs.protected_hardlinks1Prevents hardlink attacks in shared dirs
fs.protected_symlinks1Prevents symlink attacks in shared dirs
fs.protected_fifos2Blocks FIFO attacks in world-writable dirs
fs.protected_regular2Blocks regular-file attacks in world-writable dirs
dev.tty.ldisc_autoload0Stops automatic TTY line-discipline loading

Network protections

ParameterValueEffect
net.ipv4.conf.all.rp_filter2Reverse-path filtering, loose mode — deliberate, so VPN and Tor routing keep working
net.ipv4.tcp_syncookies1SYN flood protection
net.ipv4.conf.all.accept_redirects0Ignores ICMP redirect packets
net.ipv4.conf.all.send_redirects0Does not send ICMP redirects
net.ipv4.conf.all.accept_source_route0Rejects source-routed packets
net.ipv4.icmp_echo_ignore_broadcasts1Ignores broadcast ping (smurf mitigation)
net.ipv4.conf.all.log_martians1Logs packets from impossible addresses
net.ipv4.conf.default.log_martians1Same, for new interfaces
net.ipv4.conf.{all,default}.secure_redirects0Ignores even "secure" ICMP redirects
net.ipv4.icmp_ignore_bogus_error_responses1Drops malformed ICMP errors
net.ipv6.conf.{all,default}.accept_redirects0IPv6 equivalents of the above
net.ipv6.conf.{all,default}.accept_source_route0Rejects source-routed IPv6 packets

The net.ipv4.conf.default.* counterparts of the all.* entries above are set too, so interfaces appearing later inherit the same policy.


Maze Control Center — Security Tab

Open maze-control-center and select the Security tab to see the live status of every service listed here. Each service shows green (active) or red (inactive). Copyable commands let you start, stop, or enable any service from the terminal without memorizing systemctl syntax.