{"id":31584993,"url":"https://github.com/gensecaihq/ubuntu-security-hardening-script","last_synced_at":"2025-10-06T01:08:45.649Z","repository":{"id":231988717,"uuid":"783188806","full_name":"gensecaihq/Ubuntu-Security-Hardening-Script","owner":"gensecaihq","description":"This script automates the scanning process using the OpenSCAP Security Guid to hardening Ubuntu systems, aligning with DISA-STIG compliance for Ubuntu 20.04 LTS minimum. It includes a range of security enhancements and configurations designed to strengthen the security posture of Ubuntu servers.","archived":false,"fork":false,"pushed_at":"2025-03-24T07:36:41.000Z","size":24,"stargazers_count":21,"open_issues_count":2,"forks_count":3,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-06-14T08:19:20.432Z","etag":null,"topics":["disa-stig","linux","linux-hardening","linux-security","openscap","security-enhanced-linux","security-tools","server-hardening","server-security","shell-script","ubuntu","ubuntu-server","wbfoss"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/gensecaihq.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-04-07T07:17:52.000Z","updated_at":"2025-06-14T07:10:08.000Z","dependencies_parsed_at":"2024-04-07T08:26:14.895Z","dependency_job_id":"91b09be5-519b-4f2d-8bba-017965e0cde2","html_url":"https://github.com/gensecaihq/Ubuntu-Security-Hardening-Script","commit_stats":null,"previous_names":["alokemajumder/ubuntu-security-hardening-script","wbfoss/ubuntu-security-hardening-script","gensecaihq/ubuntu-security-hardening-script"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/gensecaihq/Ubuntu-Security-Hardening-Script","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FUbuntu-Security-Hardening-Script","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FUbuntu-Security-Hardening-Script/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FUbuntu-Security-Hardening-Script/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FUbuntu-Security-Hardening-Script/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/gensecaihq","download_url":"https://codeload.github.com/gensecaihq/Ubuntu-Security-Hardening-Script/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FUbuntu-Security-Hardening-Script/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":278543400,"owners_count":26004163,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-05T02:00:06.059Z","response_time":54,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["disa-stig","linux","linux-hardening","linux-security","openscap","security-enhanced-linux","security-tools","server-hardening","server-security","shell-script","ubuntu","ubuntu-server","wbfoss"],"created_at":"2025-10-06T01:08:42.881Z","updated_at":"2025-10-06T01:08:45.632Z","avatar_url":"https://github.com/gensecaihq.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Ubuntu Security Hardening Scripts\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![Ubuntu](https://img.shields.io/badge/Ubuntu-18.04%20|%2020.04%20|%2022.04%20|%2024.04%20LTS-orange)](https://ubuntu.com/)\n[![Bash](https://img.shields.io/badge/Bash-5.0%2B-green)](https://www.gnu.org/software/bash/)\n[![Security](https://img.shields.io/badge/Security-Hardening-blue)](https://github.com/alokemajumder)\n\nProduction-grade security hardening scripts for Ubuntu systems that implement comprehensive security controls, compliance configurations, and system hardening based on industry best practices.\n\n## 🚀 Features\n\n### Core Security Implementations\n- **System Updates**: Automated security patching with unattended-upgrades\n- **File Integrity Monitoring**: AIDE configuration with scheduled checks\n- **Audit System**: Comprehensive auditd rules for security monitoring\n- **Access Control**: AppArmor MAC enforcement\n- **Antivirus**: ClamAV with scheduled scanning\n- **Firewall**: UFW with secure defaults and rate limiting\n- **Intrusion Prevention**: Fail2ban with SSH and port scan protection\n- **SSH Hardening**: Crypto hardening, key-only authentication\n- **Kernel Security**: Sysctl hardening parameters\n- **System Limits**: Resource restrictions and core dump prevention\n\n### Additional Security Tools\n- **Rootkit Detection**: rkhunter and chkrootkit\n- **Security Auditing**: Lynis and Tiger\n- **Compliance Scanning**: OpenSCAP with CIS benchmarks\n- **Network Monitoring**: arpwatch and netstat analysis\n- **Package Verification**: debsums integrity checking\n\n## 📋 Requirements\n\n### System Requirements\n- Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, or 24.04 LTS\n- Minimum 2GB free disk space\n- Minimum 1GB RAM (2GB recommended)\n- Root or sudo access\n- Active internet connection for package downloads\n\n### Pre-Installation Checklist\n- [ ] Create a system backup or VM snapshot\n- [ ] Ensure SSH key access is configured (password auth will be disabled)\n- [ ] Document any custom configurations\n- [ ] Note required firewall ports for your services\n- [ ] Have console access ready (in case of SSH issues)\n\n## 🔧 Installation\n\n### Quick Start\n\n1. **Clone the repository:**\n   ```bash\n   git clone https://github.com/gensecaihq/ubuntu-security-hardening-script.git\n   cd ubuntu-security-hardening-script\n   ```\n\n2. **Make scripts executable:**\n   ```bash\n   chmod +x ubuntu-hardening-*.sh\n   ```\n\n3. **Run the appropriate script:**\n\n   **For Ubuntu 18.04/20.04/22.04:**\n   ```bash\n   sudo ./ubuntu-hardening-original.sh\n   ```\n\n   **For Ubuntu 24.04 LTS:**\n   ```bash\n   sudo ./ubuntu-hardening-24.04.sh\n   ```\n\n### Advanced Installation\n\n**With logging to file:**\n```bash\nsudo ./ubuntu-hardening-original.sh 2\u003e\u00261 | tee hardening-install.log\n```\n\n**Test mode (Ubuntu 24.04):**\n```bash\nsudo ./ubuntu-hardening-24.04.sh --test  # Coming soon\n```\n\n## 📚 Script Versions\n\n### ubuntu-hardening-original.sh\nDesigned for Ubuntu 18.04 LTS through 22.04 LTS with:\n- Traditional cron-based scheduling\n- Compatible with older package versions\n- Standard systemd configurations\n- Legacy-friendly security controls\n\n### ubuntu-hardening-24.04.sh\nOptimized for Ubuntu 24.04 LTS (Noble Numbat) with:\n- Systemd timers for all scheduled tasks\n- Ubuntu Pro/Advantage integration\n- Enhanced snap confinement\n- Modern cryptographic defaults\n- Advanced systemd security features\n- Netplan and systemd-resolved hardening\n\n## 🛡️ Security Controls Applied\n\n### 1. Authentication \u0026 Access\n- SSH root login disabled\n- Password authentication disabled\n- PAM password quality enforcement\n- Login attempt limits\n- Session timeout configuration\n\n### 2. Network Security\n- Default deny firewall policy\n- Rate-limited SSH access\n- IPv6 security (configurable)\n- TCP SYN flood protection\n- ICMP redirect prevention\n\n### 3. System Integrity\n- Daily file integrity checks\n- Comprehensive audit logging\n- Secure kernel parameters\n- Module loading restrictions\n- Core dump prevention\n\n### 4. Monitoring \u0026 Detection\n- Real-time intrusion detection\n- Rootkit scanning\n- Virus scanning with quarantine\n- Security compliance scanning\n- Automated log analysis\n\n## ⚙️ Configuration\n\n### During Installation\nThe scripts will prompt for:\n- ClamAV scan frequency (daily/weekly/monthly)\n- OpenSCAP scan frequency (daily/weekly/monthly)\n\n### Post-Installation Configuration\n\n**Add firewall rules for services:**\n```bash\nsudo ufw allow 80/tcp comment 'HTTP'\nsudo ufw allow 443/tcp comment 'HTTPS'\nsudo ufw status verbose\n```\n\n**Modify automatic update settings:**\n```bash\nsudo nano /etc/apt/apt.conf.d/50unattended-upgrades\n```\n\n**Adjust SSH settings:**\n```bash\nsudo nano /etc/ssh/sshd_config.d/99-hardening.conf\nsudo systemctl restart sshd\n```\n\n## 📊 Monitoring \u0026 Maintenance\n\n### View Security Reports\n```bash\n# Hardening report\nsudo cat /var/log/security-hardening/hardening_report_*.txt\n\n# Audit summary\nsudo aureport --summary\n\n# Failed login attempts\nsudo aureport --auth --failure\n\n# File integrity check\nsudo aide --check\n```\n\n### Security Scanning Commands\n```bash\n# System audit\nsudo lynis audit system\n\n# Rootkit check\nsudo rkhunter -c\n\n# Compliance scan (Ubuntu 24.04)\nsudo /usr/local/bin/openscap-scan.sh\n\n# Check service status\nsudo systemctl status auditd apparmor ufw fail2ban\n```\n\n### Log Locations\n- **Hardening logs**: `/var/log/security-hardening/`\n- **Audit logs**: `/var/log/audit/audit.log`\n- **ClamAV logs**: `/var/log/clamav/`\n- **UFW logs**: `/var/log/ufw.log`\n- **Fail2ban logs**: `/var/log/fail2ban.log`\n\n## 🚨 Important Warnings\n\n### ⚠️ SSH Access\n- **Password authentication is DISABLED** after hardening\n- Ensure SSH key access is working before running the script\n- Test SSH key access from another terminal before disconnecting\n- Keep a console/physical access method available\n\n### ⚠️ Firewall Rules\n- Only SSH (port 22) is allowed by default\n- All other incoming connections are blocked\n- Add rules for your required services post-installation\n\n### ⚠️ System Impact\n- Some applications may be affected by kernel hardening\n- Test all critical services after hardening\n- Review the hardening report for applied changes\n- Some parameters may need adjustment for specific workloads\n\n## 🔄 Updates and Maintenance\n\n### Automatic Updates\nThe system is configured for automatic security updates. To check status:\n```bash\nsudo systemctl status unattended-upgrades\nsudo unattended-upgrade --dry-run --debug\n```\n\n### Manual Security Updates\n```bash\n# Update package lists\nsudo apt update\n\n# Upgrade packages\nsudo apt upgrade\n\n# Update virus definitions\nsudo freshclam\n\n# Update rootkit definitions\nsudo rkhunter --update\n```\n\n## 📈 Compliance and Standards\n\nThe scripts implement controls based on:\n- CIS Ubuntu Linux Benchmarks\n- NIST Cybersecurity Framework\n- PCI DSS Requirements (where applicable)\n- Common security best practices\n\nFor compliance scanning:\n```bash\n# List available profiles\nsudo oscap info /usr/share/xml/scap/ssg/content/ssg-ubuntu*.xml\n\n# Run specific compliance check\nsudo oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_cis_level1_server \\\n    --report /tmp/cis-report.html \\\n    /usr/share/xml/scap/ssg/content/ssg-ubuntu*.xml\n```\n\n## 🐛 Troubleshooting\n\n### SSH Connection Issues\n```bash\n# If locked out, use console access and:\nsudo ufw allow ssh\nsudo systemctl restart sshd\nsudo fail2ban-client stop sshd\n```\n\n### Service Failures\n```bash\n# Check service status\nsudo systemctl status \u003cservice-name\u003e\n\n# View service logs\nsudo journalctl -u \u003cservice-name\u003e -n 50\n\n# Restart service\nsudo systemctl restart \u003cservice-name\u003e\n```\n\n### Performance Issues\n```bash\n# Disable ClamAV daemon if needed\nsudo systemctl stop clamav-daemon\nsudo systemctl disable clamav-daemon\n\n# Adjust audit rules if too verbose\nsudo auditctl -l  # List rules\nsudo auditctl -D  # Delete all rules\n```\n\n## 🤝 Contributing\n\nContributions are welcome! Please:\n1. Fork the repository\n2. Create a feature branch (`git checkout -b feature/improvement`)\n3. Commit your changes (`git commit -am 'Add new feature'`)\n4. Push to the branch (`git push origin feature/improvement`)\n5. Create a Pull Request\n\n### Development Guidelines\n- Test scripts in isolated VMs\n- Document any new features\n- Follow existing code style\n- Update this README for new functionality\n\n## 📜 License\n\nThis project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details.\n\n## ⚖️ Disclaimer\n\nThese scripts are provided \"AS IS\" without warranty of any kind. Always test in a non-production environment first. The authors are not responsible for any damage or data loss resulting from the use of these scripts.\n\n## 🙏 Acknowledgments\n\n- Ubuntu Security Team for security guidelines\n- CIS for benchmark documentation\n- Open source security tool maintainers\n- Community contributors and testers\n\n## 📞 Support\n\n- **Issues**: [GitHub Issues](https://github.com/gensecaihq/ubuntu-security-hardening-script/issues)\n\n\n## 🔗 Useful Resources\n\n- [Ubuntu Security Documentation](https://ubuntu.com/security)\n- [CIS Benchmarks](https://www.cisecurity.org/cis-benchmarks/)\n- [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework)\n- [Linux Security Modules](https://www.kernel.org/doc/html/latest/admin-guide/LSM/index.html)\n- [OpenSCAP Documentation](https://www.open-scap.org/documentation/)\n\n---\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgensecaihq%2Fubuntu-security-hardening-script","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgensecaihq%2Fubuntu-security-hardening-script","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgensecaihq%2Fubuntu-security-hardening-script/lists"}