whatis apparmor

AppArmor

A path-based mandatory access control system that confines programs with per-application profiles, default on Ubuntu, Debian, and openSUSE.

What Is AppArmor in Linux?

AppArmor profiles list which files, capabilities, and network access a specific program may use. Anything not listed is denied (in enforce mode) or just logged (in complain mode).

It is generally considered easier to write profiles for than SELinux because rules reference paths directly. aa-status shows which profiles are loaded and enforced.

Example

sudo aa-status