Open note AppArmor as an RCE Killswitch: A Blue-Team Defense Validation
An authorized blue-team assessment: exploit a trivial PHP RCE on Apache, contain it at runtime with an AppArmor profile, and then remediate the source. Includes profile snippets, audit logs, and validation output.