For security action guides, the strongest matches are forter/security-101-for-saas-startups (This repository provides a comprehensive collection of security hardening), imthenachoman/how-to-secure-a-linux-server (This repository provides a comprehensive, step-by-step hardening checklist and) and cisofy/lynis (Lynis is an automated security auditing and system hardening). owasp/cheatsheetseries and bypass007/emergency-response-notes round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Find the best security hardening guides for your infrastructure. Compare top-rated open-source checklists and pick the right one for your stack.
This project is a comprehensive set of guides and frameworks designed to secure software-as-a-service infrastructure and company operations. It provides a collection of technical checklists, architectural patterns, and best practices for hardening cloud applications against cyber attacks. The project differentiates itself by providing specialized manuals for risk management and compliance readiness. It offers structured approaches to threat modeling, incident response planning, and the preparation of audit evidence required to meet industry security certifications and enterprise customer requ
This repository provides a comprehensive collection of security hardening checklists, cloud infrastructure best practices, and actionable compliance frameworks specifically tailored for SaaS environments.
This project is a Linux server security guide and system administration manual designed to harden the operating system and kernel. It functions as an OS hardening checklist and a collection of instructions for reducing the server attack surface to protect against intruders. The guide covers the establishment of a server security baseline and the reduction of the network attack surface. It provides practical guidance for managing system permissions and network configurations to maintain a secure environment. The content is organized as a series of step-by-step procedural layouts and topic-cat
This repository provides a comprehensive, step-by-step hardening checklist and procedural guide for securing Linux infrastructure, directly addressing the core requirements for infrastructure hardening and security best practices.
Lynis is an automated security auditing and system hardening framework designed for UNIX-based operating systems. It functions as a command-line utility that inspects local system configurations to identify security vulnerabilities, configuration weaknesses, and compliance gaps. By executing a series of modular tests, the tool generates actionable reports and remediation suggestions to assist in strengthening system defenses. The project distinguishes itself through a highly modular architecture that relies on shell-script-based execution and native system inspection. Users can define custom
Lynis is an automated security auditing and system hardening tool that provides actionable remediation steps for UNIX-based infrastructure, directly addressing the need for infrastructure hardening and compliance assessment.
The OWASP Cheat Sheet Series is a comprehensive, community-driven repository of concise security best practices and defensive coding patterns. It serves as a centralized knowledge base for developers and security professionals, providing actionable guidance to secure applications across the entire software development lifecycle. The project covers a vast array of security domains, ranging from fundamental web application hardening and authentication protocols to specialized controls for modern infrastructure and artificial intelligence systems. What distinguishes this project is its decentral
This repository is a comprehensive, community-driven knowledge base that provides the exact actionable security best practices, hardening checklists, and defensive coding patterns required for infrastructure and application security.
Emergency-Response-Notes is a collection of technical reference documentation and playbooks used for performing forensic analysis, incident response, intrusion identification, and malware remediation. It serves as an incident response knowledge base and an intrusion analysis framework to help identify web shells, hidden backdoors, and persistence mechanisms used during security attacks. The project utilizes a case-study-based knowledge base to map real-world attack scenarios to specific mitigation and recovery steps. It provides a digital forensics playbook and a malware remediation guide for
This repository provides a comprehensive collection of incident response playbooks and forensic analysis guides that directly address the operational and recovery aspects of security hardening and compliance.
This project is a governance, risk, and compliance platform designed to centralize security governance, risk management, and regulatory compliance activities. It functions as a cybersecurity framework manager and a quantitative risk management system, allowing organizations to track their security posture through a centralized hub. The platform is distinguished by its ability to decouple regulatory requirements from technical security controls, enabling users to map a single implementation across multiple global frameworks to reduce audit duplication. It further differentiates itself through
This platform provides a centralized system for managing security governance, risk, and compliance frameworks, which directly supports the organizational and procedural aspects of the requested security hardening and compliance category.
This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen
This repository is a comprehensive, curated directory that aggregates security best practices, hardening checklists, and infrastructure playbooks, serving as a centralized knowledge base for the requested security domains.
Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do
This repository provides a structured, framework-aligned curriculum that serves as a comprehensive guide for security best practices, covering essential topics like incident response, identity management, and infrastructure security.
This project is a comprehensive security hardening and privacy management guide for macOS. It provides a set of instructions and checklists for reducing the system attack surface through manual configuration, policy enforcement, and a layered defense strategy. The guide emphasizes a system auditing framework, using binary analysis, system logs, and packet inspection to verify that security controls and application sandboxing are functioning as intended. It offers tool-agnostic recommendations, defining security goals while allowing users to select their own third-party software for implementa
This is a comprehensive security hardening guide that provides actionable checklists and configuration best practices for macOS, though it is limited to a single operating system rather than covering broader infrastructure or cloud compliance.
Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices. The project distinguishes itself through a comprehensive execution control system, featuring a manager for Windows Application Control and a kernel protection suite. It implements strict trust models, including kernel-mode driver whitelisting, signed policy implementation on the EFI partition, and code inte
This repository provides a comprehensive framework and set of actionable templates for hardening Windows infrastructure, directly addressing the need for security best practices and policy enforcement.
This project is a security hardening guide and privacy configuration manual for macOS. It provides a comprehensive set of instructions for configuring system settings to improve privacy, reduce the attack surface, and implement a malware defense framework. The guide covers technical methods for validating software notarization, verifying application sandboxing, and auditing system activity. It distinguishes itself by providing detailed workflows for restricting high-risk features and applying advanced security configurations to protect the operating system. The documentation covers several k
This repository provides a comprehensive, curated guide for hardening macOS systems, covering infrastructure configuration and security best practices that align with the visitor's need for actionable security documentation.
Micro8 is a security auditing knowledge base and penetration testing resource library. It serves as a curated collection of guides and documentation focused on vulnerability assessment. The project provides educational content and study guides for manual source code review, domain escalation, and internal network auditing. It includes a toolkit of reference materials for analyzing network traffic logs and identifying brute-force patterns. The library covers technical domains including web penetration testing and privilege escalation. It organizes these materials through PDF-based knowledge r
This repository serves as a curated knowledge base and reference library for security auditing and penetration testing, providing the educational guides and technical documentation needed to support infrastructure and application hardening efforts.
This project provides a comprehensive framework for incident management, offering standardized procedures and operational guidance for handling technical emergencies. It serves as a structured resource for defining incident response workflows, establishing severity classification systems, and coordinating team roles during high-stakes operational events. The documentation is maintained as version-controlled, markdown-based content, enabling collaborative updates through peer review workflows. This approach allows organizations to manage their operational knowledge as code, ensuring that proce
This repository provides a comprehensive set of incident response playbooks and operational documentation that directly addresses the incident response and team-security aspects of your search.
This project provides a comprehensive collection of conventions, patterns, and guidelines for structuring, securing, and maintaining scalable infrastructure code. It serves as a standardized resource for teams aiming to implement consistent infrastructure as code practices, focusing on the lifecycle management of cloud resources through modularization, documentation, and rigorous testing. The guide distinguishes itself by offering actionable strategies for complex infrastructure orchestration, including techniques for multi-environment management and secure state handling. It emphasizes the i
This repository provides a curated collection of best practices and configuration standards specifically for securing and managing infrastructure as code, which aligns with the infrastructure hardening aspect of your search.
This project is a comprehensive technical documentation repository focused on Linux system administration, network security, and privacy-oriented computing. It provides a curated knowledge base of instructional guides and configuration tutorials designed to assist users in managing low-level system environments, kernel compilation, and bootloader setup. The repository distinguishes itself by emphasizing privacy engineering and infrastructure hardening. It offers detailed procedures for anonymizing network traffic, securing credentials, and isolating applications within a computing environment
This repository provides a collection of technical documentation and guides covering various infrastructure and security topics, serving as a curated resource for hardening and best practices.
This project is a web application security guide and developer training resource. It serves as a secure coding framework and vulnerability remediation manual, providing software engineers with the tools to identify, prioritize, and fix common security holes across different application layers. The resource utilizes a structured verification framework and security audit checklists to systematically find vulnerabilities. It features a technical reference that maps specific security flaws to step-by-step instructions for remediation, supported by vulnerability statistics to help determine which
This repository provides a comprehensive collection of secure coding practices, vulnerability remediation guides, and security audit checklists that directly support the goal of hardening applications and infrastructure.
Go-SCP is a secure coding guide and vulnerability prevention framework for the Go programming language. It serves as a technical manual for implementing defensive programming patterns and security benchmarks to prevent common software vulnerabilities. The project functions as a static security reference, mapping known software weaknesses to specific Go remediation patterns. It provides a curated repository of secure coding standards and vetted implementation practices specifically focused on web application security. The framework covers security auditing by comparing source code against est
This repository provides a curated collection of secure coding standards and vulnerability prevention patterns specifically for the Go language, serving as a technical reference for implementing defensive programming and security best practices.
Secguide is an API security hardening framework and a comprehensive knowledge base of secure coding guidelines. It provides a multi-language security standard and a set of static analysis rules designed to identify security flaws and protect application programming interfaces from common exploits. The project functions as a reference library of security patterns and remediation guides, maintaining consistent security requirements across various programming languages. It utilizes rule-based pattern matching and a static analysis pipeline to detect dangerous API calls and vulnerabilities within
This repository serves as a comprehensive knowledge base and reference library for secure coding standards and API hardening, directly addressing the need for curated security best practices and remediation guidance.
This project is a comprehensive security suite and knowledge base focused on the engineering and construction of trustworthy digital and physical systems. It provides a systematic framework for security engineering design, covering the establishment of high-assurance architectures and the implementation of security models that govern how a system achieves its safety goals. The project is distinguished by its focus on formal assurance and adversarial deterrence. It includes methodologies for creating security assurance cases and proofs to verify system trustworthiness, alongside economic and t
This repository provides a systematic knowledge base and framework for security engineering, offering the high-level methodologies and architectural hardening principles required to build and secure complex systems.
The Proxmox Hardening Guide project provides structured, actionable recommendations to secure Proxmox Virtual Environment (PVE 9.x & 8.x) and Proxmox Backup Server (PBS 4.x & 3.x).
This repository provides a structured, actionable hardening guide specifically for Proxmox infrastructure, directly addressing the need for security best practices and infrastructure hardening.
Read this in other languages: English, 简体中文.
This repository provides a curated collection of security practices and hardening guidelines that directly address infrastructure and application security, serving as a practical resource for the requested category.
This repository provides a specialized collection of security audit standards and hardening practices tailored for cryptocurrency projects, serving as a focused guide for infrastructure and application security.
| 仓库 | Star 数 | 语言 | 许可证 | 最后推送 |
|---|---|---|---|---|
| forter/security-101-for-saas-startups | 4.6K | — | NOASSERTION | |
| imthenachoman/how-to-secure-a-linux-server | 27.8K | — | CC-BY-SA-4.0 | |
| cisofy/lynis | 15.3K | Shell | gpl-3.0 | |
| owasp/cheatsheetseries | 32.3K | Python | CC-BY-SA-4.0 | |
| bypass007/emergency-response-notes | 5.6K | — | — | |
| intuitem/ciso-assistant-community | 4.2K | Python | NOASSERTION | |
| sbilly/awesome-security | 14K | — | mit | |
| microsoft/security-101 | 6.2K | HTML | cc0-1.0 | |
| drduh/os-x-security-and-privacy-guide | 22.4K | — | MIT | |
| hotcakex/harden-windows-security | 4.1K | C# | mit |