From "Systemd service sandboxing and security hardening" (2022) https://news.ycombinator.com/item?id=29995566 :
> Which distro has the best out-of-the-box output for:?
systemd-analyze security
And e.g. this in systemd units: SystemCallFilter=@basic-io
SystemCallLog=~@basic-io