There are 58 repositories under hardening topic.
An evolving how-to guide for securing a Linux server.
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments & audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, ENS and more
Community guide to using YubiKey for GnuPG and SSH - protect secrets with hardware crypto.
This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL
Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.
Security automation content in SCAP, Bash, Ansible, and other formats
HardeningKitty and Windows Hardening Settings
A curated list of awesome Security Hardening techniques for Windows.
Windows 10/11 Guide. Including Windows Security tools, Encryption, Nextcloud, Graphics, Gaming, Virtualization, Windows Subsystem for Linux (WSL 2), Software Apps, and Resources.
HardeningKitty - Checks and hardens your Windows configuration
Hardening Ubuntu. Systemd edition.
Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.
🔥 A powerful MongoDB auditing and pentesting tool 🔥
Enhance the security and privacy of your Windows 10 and Windows 11 deployments with our fully optimized, hardened, and debloated script. Adhere to industry best practices and Department of Defense STIG/SRG requirements for optimal performance and security.
a collection about Windows 11
Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.
Easily configure macOS security settings from the terminal.
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!
DevSec Linux Baseline - InSpec Profile
This Ansible role provides numerous security-related ssh configurations, providing all-round base protection.
Full set of AppArmor policies
Ansible role to apply a security baseline. Systemd edition.
Rudder is a configuration and security automation platform. Manage your Cloud, hybrid or on-premises infrastructure in a simple, scalable and dynamic way.
CIS Docker Benchmark - InSpec Profile
This repository is a collection of resources to prepare for the Certified Kubernetes Security Specialist (CKSS) exam.
Security Auditor Utility for GraphQL APIs
This chef cookbook provides numerous security-related configurations, providing all-round base protection.