-
Updated
May 1, 2021
#
security-hardening
Here are 257 public repositories matching this topic...
An evolving how-to guide for securing a Linux server.
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
linux
shell
auditing
devops
unix
security-audit
pci-dss
compliance
hardening
security-vulnerability
security-hardening
devops-tools
hipaa
vulnerability-detection
vulnerability-scanners
security-scanner
vulnerability-assessment
gdpr
security-tools
system-hardening
-
Updated
Sep 1, 2021 - Shell
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
go
linux
golang
freebsd
security
security-audit
administrator
cybersecurity
security-vulnerability
vulnerabilities
security-hardening
vulnerability-detection
vulnerability-management
vulnerability-scanners
security-scanner
vulnerability-assessment
vuls
security-automation
security-tools
vulnerability-scanner
-
Updated
Sep 16, 2021 - Go
Prowler is a security tool to perform AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It contains all CIS controls and many more additional checks that help on GDPR, HIPAA and other security frameworks.
aws
security
cis
security-audit
cloud
aws-cli
assessment
forensics
compliance
hardening
security-hardening
hipaa
cloudtrail
gdpr
security-tools
devsecops
cis-benchmark
aws-auditing
prowler
well-architected
-
Updated
Sep 16, 2021 - Shell
Wazuh - The Open Source Security Platform
security
elasticsearch
log-analysis
monitoring
incident-response
ids
intrusion-detection
pci-dss
compliance
security-hardening
loganalyzer
vulnerability-detection
ossec
openscap
wazuh
policy-monitoring
security-awareness
file-integrity-management
-
Updated
Sep 17, 2021 - C
user.js -- Firefox configuration hardening
-
Updated
Sep 12, 2021 - JavaScript
Migrate C code to Rust
-
Updated
Aug 29, 2021 - Rust
Librefox: Firefox with privacy enhancements
firefox
security
privacy
browser
addon
freedom
mozilla
android-application
free-software
libre
mac-app
android-app
security-hardening
linux-app
mozilla-firefox
windows-app
anti-fingerprinting
libresoftware
libre-software
extensions-firewall
-
Updated
Mar 28, 2021 - JavaScript
Security automation content in SCAP, OSCAL, Bash, Ansible, and other formats
security
ansible
cybersecurity
pci-dss
application-security
compliance
scap
hardening
security-hardening
xccdf
oval
cpe
information-security
cce
usgcb
ospp
stig
security-automation
security-tools
security-profile
-
Updated
Sep 17, 2021 - Python
Generates sandboxes for C/C++ libraries automatically
-
Updated
Sep 16, 2021 - C++
rails
checklist
security
security-audit
ruby-on-rails
security-hardening
rails-security
rails-security-checklist
-
Updated
Jul 26, 2020 - Ruby
Simple Golang HTTPS/TLS Examples
go
golang
security
security-audit
awesome
tools
openssl
https
http2
secure
httpclient
libressl
security-hardening
https-server
security-scanner
security-tools
-
Updated
Nov 20, 2020
A collection of awesome security hardening guides, tools and other resources
security
best-practices
cybersecurity
infosec
awesome-list
security-hardening
cyber-security
computer-security
blueteam
security-tools
blue-team
linux-hardening
cis-benchmarks
windows-hardening
-
Updated
Jun 29, 2021
Hardening Ubuntu. Systemd edition.
shell
security
ubuntu
systemd
hardening
ubuntu-server
security-hardening
information-security
security-automation
security-tools
security-compliance
-
Updated
Sep 7, 2021 - Shell
Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.
aws
security
devops
terraform
hardening
security-hardening
terraform-modules
security-tools
cis-benchmark
aws-auditing
-
Updated
Sep 12, 2021 - HCL
USBGuard is a software framework for implementing USB device authorization policies (what kind of USB devices are authorized) as well as method of use policies (how a USB device may interact with the system)
linux
security
c-plus-plus
whitelist
blacklist
usb
security-hardening
usb-devices
rule-language
hacktoberfest
-
Updated
Sep 15, 2021 - C++
The Hitchhiker’s Guide to Online Anonymity
security
privacy
gpg
tor
activism
anticensorship
anonymity
security-hardening
qubes-os
privacy-policy
privacy-enhancing-technologies
privacy-online
privacy-protection
veracrypt
anonymization
tails
whonix
privacy-aware
privacy-tools
privacy-by-design
-
Updated
Sep 14, 2021 - HTML
Security Knowledge Framework (SKF) Python Flask / Angular project
security
security-audit
secure-by-default
security-hardening
security-training
secure-coding
security-framework
security-standards
owasp-skf
security-knowledge
security-requirements
-
Updated
Sep 16, 2021 - HTML
WhiteWinterWolf
commented
May 1, 2021
I'm not confident in the security brought by the readonly_exec
statement.
In the classical *nix DAC model, it is expected for unprivileged users to be able to change the write permission flag on files they own. Therefore, Snuffleupagus readonly_exec
statement only relies on the hope that an attacker won't find a way to rely on this standard mechanism to prevent the execution of arbitrary
Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark
linux
iptables
centos7
ubuntu1604
hardening
ubuntu-server
security-hardening
modsecurity
linux-server
lamp-stack
system-hardening
cis-benchmark
ubuntu1804
hardening-steps
lamp-deployer
lemp-deployer
-
Updated
Sep 21, 2020 - PHP
Ansible playbook roles for security
-
Updated
Sep 7, 2018
Scripts built from our Guide to User Data Security
-
Updated
Oct 21, 2018 - Shell
-
Updated
Sep 13, 2021 - JavaScript
Kubernetes RBAC static Analysis & visualisation tool
kubernetes
security
analysis
static-analysis
visualisation
rbac
k8s
role-based-access-control
security-hardening
security-scanner
security-tools
rbac-management
rbac-configuration
redisgraph
rbac-roles
-
Updated
Aug 12, 2021 - Ruby
Open-source tool to enforce privacy & security best-practices on Windows and macOS, because privacy is sexy 🍑 🍆
macos
vuejs
privacy
domain-driven-design
macosx
cleanup
windows10
bloatware
security-hardening
tweaks-collection
security-tools
privacy-protection
debloat
privacy-tools
debotnet
spybot
debloater
bloatware-removal
-
Updated
Sep 14, 2021 - TypeScript
Quickly secure UNIX/Linux systems
-
Updated
Mar 9, 2020 - Shell
Ansible role for Red Hat 7 CIS Baseline
-
Updated
Sep 15, 2021 - Jinja
Continuously monitor your AWS services for configurations that can lead to degradation of confidentiality, integrity or availability. All results will be sent to Security Hub for further aggregation and analysis.
aws
security-audit
automation
monitoring
terraform
audit
security-hardening
aws-security
risk-management
monitoring-tool
security-tools
soar
security-engineering
cloud-security
cloud-auditing
security-monitoring
well-architected
cloud-compliance-reporting
security-hub
continuous-compliance
-
Updated
Sep 2, 2021 - Python
Improve this page
Add a description, image, and links to the security-hardening topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the security-hardening topic, visit your repo's landing page and select "manage topics."
https://github.com/0xmachos/mOSL is a good replacement until this is updated.
Basically, we should remove all settings that are no longer relevant, and add ones that are newly added.