>>105893988 (OP)Just do some basic hardening like partitioning with noexec, nosuid, nodev, ro aptly applied, some binding (like /tmp and /var/tmp), setting selinux or apparmor+firejail, setting up some situational iptable profiles and you're mostly good, wtf do you even need more?