2 ExecStart=/usr/bin/imaginary -a localhost
8 ProtectKernelModules=true
9 ProtectKernelTunables=true
14 ProtectControlGroups=true
15 ProtectKernelLogs=true
18 CapabilityBoundingSet=
19 MemoryDenyWriteExecute=true
20 CapabilityBoundingSet=CAP_NET_RAW
21 AmbientCapabilities=CAP_NET_RAW
24 WantedBy=default.target