Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
awesome-security-hardening
https://github.com/merlinepedra25/awesome-security-hardening
Last synced: 5 days ago
JSON representation
-
GNU/Linux
-
- trimstray - The Practical Linux Hardening Guide - practical step-by-step instructions for building your own hardened systems and services. Tested on CentOS 7 and RHEL 7.
- trimstray - Linux Hardening Checklist - most important hardening rules for GNU/Linux systems (summarized version of The Practical Linux Hardening Guide)
- How To Secure A Linux Server - for a single Linux server at home
- Neo23x0/auditd - Best Practice Auditd Configuration
- ANSSI - Configuration recommendations of a GNU/Linux system
- nixCraft - 40 Linux Server Hardening Security Tips (2019 edition)
- nixCraft - Tips To Protect Linux Servers Physical Console Access
- TecMint - 4 Ways to Disable Root Account in Linux
- ERNW - IPv6 Hardening Guide for Linux Servers
-
Red Hat Enterprise Linux - RHEL
-
CentOS
-
SUSE
-
Ubuntu
-
-
Windows
-
Ubuntu
- Awesome Windows Domain Hardening
- NSA - AppLocker Guidance - Configuration guidance for implementing application whitelisting with AppLocker
- NSA - Pass the Hash Guidance - Configuration guidance for implementing Pass-the-Hash mitigations (Archived)
- NSA - BitLocker Guidance - Configuration guidance for implementing disk encryption with BitLocker
- NSA - Event Forwarding Guidance - Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding
- BSI/ERNW - Configuration Recommendations for Hardening of Windows 10 Using Built-in Functionalities - focused on Windows 10 LTSC 2019
- ACSC - Hardening Microsoft Windows 10, version 21H1, Workstations
- ACSC - Securing PowerShell in the Enterprise
- Windows Defense in Depth Strategies - work in progress
- Endpoint Isolation with the Windows Firewall - Zealand-2016/M377) talk from Ignite 2016
- ERNW - IPv6 Hardening Guide for Windows Servers
- Microsoft - How to detect, enable and disable SMBv1, SMBv2, and SMBv3 in Windows and Windows Server
- Microsoft recommended block rules - List of applications or files that can be used by an attacker to circumvent application whitelisting policies
-
-
Virtualization - VMware
-
Firewalls
- ANSSI - Recommandations de sécurité pour les architectures basées sur VMware vSphere ESXi - for VMware 5.5 (2016), in French
- ANSSI - Problématiques de sécurité associées à la virtualisation des systèmes d’information
- VMware Security Hardening Guides - covers most VMware products and versions
- DISA STIGs - Virtualisation - VMware vSphere 6.0 and 5
- ENISA - Security aspects of virtualization - generic, high-level best practices for virtualization and containers (Feb 2017)
- NIST SP 800-125 - Guide to Security for Full Virtualization Technologies - (2011)
- NIST SP 800-125B Secure Virtual Network Configuration for Virtual Machine (VM) Protection
-
-
Containers - Docker
-
Services
-
SSH
-
TLS/SSL
- ANSSI - Security Recommendations for TLS - 2017, does not cover TLS 1.3
- Netherlands NCSC - IT Security Guidelines for Transport Layer Security (TLS) - 2019
- Qualys SSL Labs - SSL and TLS Deployment Best Practices - 2017, does not cover TLS 1.3
- Applied Crypto Hardening: bettercrypto.org - handy reference on how to configure the most common services’ crypto settings (TLS/SSL, PGP, SSH and other cryptographic tools)
-
Web Servers
- Cipherli.st - Strong Ciphers for Apache, nginx and Lighttpd
- GeekFlare - Apache Web Server Hardening and Security Guide
- Apache Config - Apache Security Hardening Guide
- Apache Tomcat 9 Security Considerations - 8.0-doc/security-howto.html) / [v7](https://tomcat.apache.org/tomcat-7.0-doc/security-howto.html)
- How to get Tomcat 9 to work with authbind to bind to port 80
- Eclipse Jetty - Configuring Security
- Jetty hardening
- CIS Microsoft IIS Benchmarks
-
Active Directory
- ANSSI CERT-FR - Active Directory Security Assessment Checklist - 2020 (English and French versions)
-
ADFS
-
LDAP
-
DNS
-
NFS
- Red Hat - RHEL7 Storage Administration Guide - Securing NFS
- NFSv4 without Kerberos and permissions - why NFSv4 without Kerberos does not provide security
- CertDepot - RHEL7: Use Kerberos to control access to NFS network shares
-
CUPS
-
-
Hardening Guide Collections
- ANSSI Best Practices
- NSA Security Configuration Guidance
- NSA Cybersecurity Resources for Cybersecurity Professionals
- US DoD DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)
- OpenSCAP Security Policies
- Australian Cyber Security Center Publications
- FIRST Best Practice Guide Library (BPGL)
-
Network Devices
-
Authentication - Passwords
-
Hardware - CPU - BIOS - UEFI
-
CUPS
- NSA Info Sheet: UEFI Lockdown Quick Guidance (March 2018)
- NSA Tech Report: UEFI Defensive Practices Guidance (July 2017)
- ANSSI - Hardware security requirements for x86 platforms - recommendations for security features and configuration options applying to hardware devices (CPU, BIOS, UEFI, etc) (Nov 2019)
-
-
Cloud
-
CUPS
- NSA Info Sheet: Cloud Security Basics (August 2018)
- DISA DoD Cloud Computing Security
- asecure.cloud - Build a Secure Cloud - A free repository of customizable AWS security configurations and best practices
-
-
Tools to check security hardening
-
GNU/Linux
- Lynis - script to check the configuration of Linux hosts
- OpenSCAP Base - oscap command line tool
- SCAP Workbench - GUI for oscap
- Tiger - The Unix security audit and intrusion detection tool
-
Windows
- PingCastle - Tool to check the security of Active Directory
-
TLS/SSL
- Qualys SSL Labs - List of tools to assess TLS/SSL servers and clients
- SSL Decoder - checks the SSL/TLS configuration of a server
-
-
Tools to apply security hardening
-
Cloud
- DevSec Hardening Framework - a framework to automate hardening of OS and applications, using Chef, Ansible and Puppet
-
Windows
- mackwage/windows_hardening.cmd - Script to perform some hardening of Windows 10
-
TLS/SSL
-
-
Password Generators
-
Cloud
- Vitux - 8 Ways to Generate a Random Password on Linux Shell
- SS64 - Password security and a comparison of Password Generators
- Awesome Cybersecurity Blue Team - A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
-
-
Other Awesome Security Lists
-
Cloud
- Android Security Awesome - A collection of android security related resources.
- Awesome CTF - A curated list of CTF frameworks, libraries, resources and software.
- Awesome Hacking - A curated list of awesome Hacking tutorials, tools and resources.
- Awesome Honeypots - An awesome list of honeypot resources.
- Awesome Malware Analysis - A curated list of awesome malware analysis tools and resources.
- Awesome PCAP Tools - A collection of tools developed by other researchers in the Computer Science area to process network traces.
- Awesome Linux Containers - A curated list of awesome Linux Containers frameworks, libraries and software.
- Awesome Incident Response - A curated list of resources for incident response.
- Awesome Crypto Papers - A curated list of cryptography papers, articles, tutorials and howtos.
- Awesome Security - A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
-
-
macOS
Programming Languages
Categories
Services
27
GNU/Linux
17
Windows
13
Other Awesome Security Lists
10
Hardening Guide Collections
7
Tools to check security hardening
7
Virtualization - VMware
7
Containers - Docker
4
Network Devices
4
Cloud
3
Password Generators
3
Authentication - Passwords
3
Tools to apply security hardening
3
Hardware - CPU - BIOS - UEFI
3
macOS
1
Sub Categories
Keywords
awesome
8
security
8
awesome-list
7
windows
5
list
4
hardening
3
audit
2
cybersecurity
2
linux
2
whitelisting
1
pass-the-hash
1
pth
1
bitlocker
1
bitlocker-drive-encryption
1
encryption
1
full-disk-encryption
1
guidance
1
microsoft
1
nessus
1
event-log
1
siem
1
blue-team
1
computer-security
1
centos
1
checklist
1
cis
1
guide
1
linux-hardening
1
linux-security
1
manual
1
openscap
1
pci-dss
1
redhat-enterprise-linux
1
cc-by-sa
1
hardening-steps
1
linux-server
1
security-hardening
1
server
1
application-whitelisting
1
applocker
1
microsoft-applocker
1
defensive-security
1
threat-intelligence
1
threat-sharing
1
threatintel
1
best-practices
1
containers
1
linux-containers
1
dfir
1
incident-response
1