The tkprof utility must be removed from production environments; it is a powerful tool for an attacker to find issues in the running database. Level 1, Scorable NOTE: Change ORACLE_HOME to the full path to your organization's Oracle directory. ref: https://benchmarks.cisecurity.org/tools2/oracle/CIS_Oracle_11g_Benchmark_v1.0.1.pdf, pg 12.