There are 63 repositories under hardening topic.
An evolving how-to guide for securing a Linux server.
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Prowler is the Open Cloud Security for AWS, Azure, GCP, Kubernetes, M365 and more. As agent-less, it helps for continuous monitoring, security assessments & audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, ENS and more
Community guide to using YubiKey for GnuPG and SSH - protect secrets with hardware crypto.
This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL
Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.
Security automation content in SCAP, Bash, Ansible, and other formats
HardeningKitty and Windows Hardening Settings
A curated list of awesome Security Hardening techniques for Windows.
Windows 10/11 Guide. Including Windows Security tools, Encryption, Nextcloud, Graphics, Gaming, Virtualization, Windows Subsystem for Linux (WSL 2), Software Apps, and Resources.
HardeningKitty - Checks and hardens your Windows configuration
Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.
Hardening Ubuntu. Systemd edition.
🔥 A powerful MongoDB auditing and pentesting tool 🔥
Enhance the security and privacy of your Windows 10 and Windows 11 deployments with our fully optimized, hardened, and debloated script. Adhere to industry best practices and Department of Defense STIG/SRG requirements for optimal performance and security.
a collection about Windows 11
Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.
Easily configure macOS security settings from the terminal.
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
DevSec Linux Baseline - InSpec Profile
Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!
This Ansible role provides numerous security-related ssh configurations, providing all-round base protection.
Full set of AppArmor policies
Ansible role to apply a security baseline. Systemd edition.
Rudder is a configuration and security automation platform. Manage your Cloud, hybrid or on-premises infrastructure in a simple, scalable and dynamic way.
Security Auditor Utility for GraphQL APIs
CIS Docker Benchmark - InSpec Profile
This repository is a collection of resources to prepare for the Certified Kubernetes Security Specialist (CKSS) exam.