[Unit] Description=Executable Guardian for %I After=network.target StartLimitIntervalSec=60 StartLimitBurst=3 [Service] ExecStart=/usr/local/bin/execguard --%I Restart=on-failure RestartSec=2 SuccessExitStatus=0 4 RestartForceExitStatus=0 4 # Hardening MemoryDenyWriteExecute=true NoNewPrivileges=true SystemCallArchitectures=native RestrictSUIDSGID=yes RestrictRealtime=yes [Install] WantedBy=multi-user.target