An evolving how-to guide for securing a Linux server.
-
Updated
Jan 21, 2020
An evolving how-to guide for securing a Linux server.
This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Prowler is a security tool to perform AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It contains all CIS controls listed here https://d0.awsstatic.com/whitepapers/compliance/AWS_CIS_Foundations_Benchmark.pdf and more than 100 additional checks that help on GDPR, HIPAA and other security requirements.
This Ansible role provides numerous security-related configurations, providing all-round base protection.
Security automation content in SCAP, OSCAL, Bash, Ansible, and other formats
Easily configure macOS security settings from the terminal.
This Ansible role provides numerous security-related ssh configurations, providing all-round base protection.
Automated System Hardening Framework
AWS Auditing & Hardening Tool
Hardening Ubuntu. Systemd edition.
Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark
Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations.
Security module for php7 - Killing bugclasses and virtual-patching the rest!
Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.
CIS Docker Benchmark - InSpec Profile
HardenedBSD development tree.
Better AWS SSM Session manager CLI client
Add a description, image, and links to the hardening topic page so that developers can more easily learn about it.
To associate your repository with the hardening topic, visit your repo's landing page and select "manage topics."