Binary Hardening Audit

Checks 8 security mitigations and correlates with detected bugs.

Usage

memguard harden /tmp/binary
memguard harden /tmp/binary --scan <scan-id>

# Compare normal vs hardened
gcc -g -O2 -fPIE -pie -fstack-protector-strong \
    -D_FORTIFY_SOURCE=2 -Wl,-z,relro,-z,now \
    -o /tmp/hardened src/main.c
memguard harden /tmp/hardened --scan <scan-id>

Checks: PIE, Stack Canary, NX, RELRO, FORTIFY_SOURCE, Sanitizer, Debug Info, ASLR.

Exploit levels: TRIVIAL (3+ missing) / LIKELY (2) / POSSIBLE (1) / UNLIKELY (all enabled).