awesome-repositories.com
المدونة
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعحولكيفية ترتيب النتائجالصحافةخادم MCP
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
trimstray avatar

trimstray/the-practical-linux-hardening-guide

0
View on GitHub↗
10,545 نجوم·668 تفرعات·MIT·5 مشاهدات

The Practical Linux Hardening Guide

This project is a comprehensive Linux server hardening guide and infrastructure documentation resource. It provides a set of validated security baselines and step-by-step instructions for implementing security controls and configuration best practices to protect production environments.

The guide focuses on aligning systems with industry-standard security benchmarks, specifically those provided by the Center for Internet Security and Security Technical Implementation Guides. It includes a framework for using OpenSCAP to scan system configurations, verify compliance against reference profiles, and generate detailed auditing reports.

The documentation covers the application of strict directory permissions, the implementation of standardized security baselines, and the use of automation tools to consistently apply hardening workflows across multiple servers.

Features

  • Linux Security Hardening - Implements industry-standard security configurations to harden Linux production environments against threats.
  • CIS Baseline Implementations - Configures the operating system following Center for Internet Security recommendations to ensure a hardened production environment.
  • Compliance & Audit Tools - Uses OpenSCAP to scan configurations against security benchmarks and generate compliance reports.
  • File System Permissions - Implements strict directory and file system permissions to prevent unauthorized access and privilege escalation.
  • Configuration Scanning - Provides a framework for using OpenSCAP to scan system configurations and verify compliance against reference profiles.
  • Security Standards - Implements validated configuration standards and technical benchmarks to reduce the system attack surface.
  • Policy-Based Access Control - Automates strict directory and file access controls using policy-based enforcement.
  • CIS Benchmark Implementations - Provides configuration standards and instructions for aligning Linux operating systems with CIS security baselines.
  • STIG Implementations - Implements specific security technical implementation guides to restrict system access and mitigate known attack vectors.
  • Server Hardening - Provides automated application of security configurations and directory permissions for server hardening.
  • Benchmark-Driven Configurations - Applies security settings based on validated reference profiles from industry standards like CIS and STIG.
  • Security Automation Workflows - Provides automated workflows for applying security configurations and baselines across production servers.
  • Hardening Configuration Automations - Applies consistent security baselines and hardening settings across multiple servers using automation.
  • Reference Profile Validations - Compares the current system state against predefined security baselines to verify the effectiveness of implemented controls.
  • Security Benchmarking - Implements a methodology for scanning configurations and generating reports against C2S, CIS, and STIG benchmarks.
  • Audit and Compliance - Scans system configurations and generates reports to verify adherence to security benchmarks.
  • Security and Compliance - Combines technical security controls with monitoring and reporting to evaluate policy compliance.
  • System Access Restrictions - Provides technical implementation guides for restricting system access to meet government security requirements.
  • Technical Implementation Guides - Implements Security Technical Implementation Guides to ensure Linux systems meet strict government and industry requirements.
  • Infrastructure - Automates the application of security settings based on predefined industry standards and organizational security baselines.
  • Security Benchmark Validations - Verifies the effectiveness of security controls by comparing current system states against validated reference profiles.
  • Linux Hardening - Step-by-step instructions for building hardened Linux systems.

سجل النجوم

مخطط تاريخ النجوم لـ trimstray/the-practical-linux-hardening-guideمخطط تاريخ النجوم لـ trimstray/the-practical-linux-hardening-guide

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Start searching with AI

الأسئلة الشائعة

ما هي وظيفة trimstray/the-practical-linux-hardening-guide؟

This project is a comprehensive Linux server hardening guide and infrastructure documentation resource. It provides a set of validated security baselines and step-by-step instructions for implementing security controls and configuration best practices to protect production environments.

ما هي الميزات الرئيسية لـ trimstray/the-practical-linux-hardening-guide؟

الميزات الرئيسية لـ trimstray/the-practical-linux-hardening-guide هي: Linux Security Hardening, CIS Baseline Implementations, Compliance & Audit Tools, File System Permissions, Configuration Scanning, Security Standards, Policy-Based Access Control, CIS Benchmark Implementations.

ما هي البدائل مفتوحة المصدر لـ trimstray/the-practical-linux-hardening-guide؟

تشمل البدائل مفتوحة المصدر لـ trimstray/the-practical-linux-hardening-guide: docker/docker-bench-security — This project is a security compliance tool and configuration auditor designed to evaluate Docker deployments against… voltagent/awesome-claude-code-subagents — This project provides a framework for managing multi-agent systems, designed to automate complex software development,… aws/aws-cdk — The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision… trimstray/test-your-sysadmin-skills — This project is a Linux system administration question bank designed to evaluate knowledge of server management. It… geerlingguy/ansible-for-devops — This project is an infrastructure as code framework and library of reusable playbooks designed for server… imthenachoman/how-to-secure-a-linux-server — This project is a Linux server security guide and system administration manual designed to harden the operating system…

بدائل مفتوحة المصدر لـ The Practical Linux Hardening Guide

مشاريع مفتوحة المصدر مشابهة، مرتبة حسب عدد الميزات المشتركة مع The Practical Linux Hardening Guide.
  • docker/docker-bench-securityالصورة الرمزية لـ docker

    docker/docker-bench-security

    9,655عرض على GitHub↗

    This project is a security compliance tool and configuration auditor designed to evaluate Docker deployments against industry security benchmarks. It functions as a script-based scanner that identifies misconfigurations and vulnerabilities within both the host operating system and container settings. The tool specifically implements the Center for Internet Security standards for Docker to verify host and container configurations. It enables a hardening workflow by comparing system states against these standards to identify security gaps and document compliance status. The audit engine suppor

    Shell
    عرض على GitHub↗9,655
  • voltagent/awesome-claude-code-subagentsالصورة الرمزية لـ VoltAgent

    VoltAgent/awesome-claude-code-subagents

    21,906عرض على GitHub↗

    This project provides a framework for managing multi-agent systems, designed to automate complex software development, infrastructure, and business workflows. It functions as a multi-agent workflow orchestrator that routes tasks to domain-specific workers while maintaining state persistence and infrastructure automation. By leveraging large language models, the system decomposes high-level objectives into actionable plans, ensuring that complex operations are executed with consistency and reliability. The framework distinguishes itself through its hierarchical agent registry and policy-driven

    Shellai-agent-frameworkai-agent-toolsai-agents
    عرض على GitHub↗21,906
  • aws/aws-cdkالصورة الرمزية لـ aws

    aws/aws-cdk

    12,817عرض على GitHub↗

    The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It

    TypeScriptawscloud-infrastructurehacktoberfest
    عرض على GitHub↗12,817
  • trimstray/test-your-sysadmin-skillsالصورة الرمزية لـ trimstray

    trimstray/test-your-sysadmin-skills

    11,667عرض على GitHub↗

    This project is a Linux system administration question bank designed to evaluate knowledge of server management. It serves as a technical reference and study guide through a collection of curated questions and answers. The resource provides targeted preparation for technical interviews and professional exams. It specifically covers DevOps interview preparation, including containerization, continuous integration, and version control. The knowledge base spans several core competency areas, including system internals, kernel architectures, and the Linux boot process. It also includes materials

    answersbsdcheatsheets
    عرض على GitHub↗11,667
عرض جميع البدائل الـ 30 لـ The Practical Linux Hardening Guide→