An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with hardening

A curated list of projects in awesome lists tagged with hardening .

https://github.com/cisofy/lynis

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

auditing compliance devops devops-tools gdpr hardening hipaa linux pci-dss security-audit security-hardening security-scanner security-tools security-vulnerability shell system-hardening unix vulnerability-assessment vulnerability-detection vulnerability-scanners

Last synced: 14 May 2025

https://github.com/CISOfy/Lynis

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

auditing compliance devops devops-tools gdpr hardening hipaa linux pci-dss security-audit security-hardening security-scanner security-tools security-vulnerability shell system-hardening unix vulnerability-assessment vulnerability-detection vulnerability-scanners

Last synced: 11 May 2025

https://github.com/CISOfy/lynis

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

auditing compliance devops devops-tools gdpr hardening hipaa linux pci-dss security-audit security-hardening security-scanner security-tools security-vulnerability shell system-hardening unix vulnerability-assessment vulnerability-detection vulnerability-scanners

Last synced: 26 Mar 2025

https://github.com/prowler-cloud/prowler

Prowler is an Open Cloud Security Platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, ENS and more

aws azure cis-benchmark cloud cloudsecurity compliance cspm devsecops forensics gcp gdpr hardening iam multi-cloud python security security-audit security-hardening security-tools well-architected

Last synced: 13 May 2025

https://github.com/trimstray/the-practical-linux-hardening-guide

This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).

audit centos checklist cis guide hardening linux linux-hardening linux-security manual openscap pci-dss redhat-enterprise-linux security

Last synced: 14 May 2025

https://github.com/hardentools/hardentools

Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.

hardening security windows

Last synced: 31 Mar 2025

https://github.com/mikeroyal/Windows-11-Guide

Windows 10/11 Guide. Including Windows Security tools, Encryption, Nextcloud, Graphics, Gaming, Virtualization, Windows Subsystem for Linux (WSL 2), Software Apps, and Resources.

active-directory debloat gaming hardening nextcloud optimization privacy-protection tweaks uwp visual-studio-code windows-11 windows-defender windows-desktop windows-subsystem-linux windows-terminal windows10 windows11 winui winui3 wsl

Last synced: 09 Apr 2025

https://github.com/mikeroyal/windows-11-guide

Windows 10/11 Guide. Including Windows Security tools, Encryption, Nextcloud, Graphics, Gaming, Virtualization, Windows Subsystem for Linux (WSL 2), Software Apps, and Resources.

active-directory debloat gaming hardening nextcloud optimization privacy-protection tweaks uwp visual-studio-code windows-11 windows-defender windows-desktop windows-subsystem-linux windows-terminal windows10 windows11 winui winui3 wsl

Last synced: 15 May 2025

https://github.com/scipag/hardeningkitty

HardeningKitty - Checks and hardens your Windows configuration

audit blueteam checklist defense hardening powershell registry security windows windows-10 windows-server

Last synced: 14 May 2025

https://github.com/scipag/HardeningKitty

HardeningKitty - Checks and hardens your Windows configuration

audit blueteam checklist defense hardening powershell registry security windows windows-10 windows-server

Last synced: 09 Apr 2025

https://github.com/grapheneos/hardened_malloc

Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.

grapheneos hardening malloc malloc-library memory memory-allocation memory-allocator quarantine security slab-allocator

Last synced: 14 May 2025

https://github.com/GrapheneOS/hardened_malloc

Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.

grapheneos hardening malloc malloc-library memory memory-allocation memory-allocator quarantine security slab-allocator

Last synced: 08 May 2025

https://github.com/stampery/mongoaudit

🔥 A powerful MongoDB auditing and pentesting tool 🔥

authentication cli database encryption hardening infosec mongodb pentesting

Last synced: 15 May 2025

https://github.com/simeononsecurity/windows-optimize-harden-debloat

Enhance the security and privacy of your Windows 10 and Windows 11 deployments with our fully optimized, hardened, and debloated script. Adhere to industry best practices and Department of Defense STIG/SRG requirements for optimal performance and security.

automation cyber debloat debotnet harden hardening hardware-requirements microsoft mitigations privacy privacy-script security stig-compliant stigs telemetry windows windows-10 windows-defender windows-desktop windows10

Last synced: 14 May 2025

https://github.com/simeononsecurity/Windows-Optimize-Harden-Debloat

Enhance the security and privacy of your Windows 10 and Windows 11 deployments with our fully optimized, hardened, and debloated script. Adhere to industry best practices and Department of Defense STIG/SRG requirements for optimal performance and security.

automation cyber debloat debotnet harden hardening hardware-requirements microsoft mitigations privacy privacy-script security stig-compliant stigs telemetry windows windows-10 windows-defender windows-desktop windows10

Last synced: 09 Apr 2025

https://github.com/nozaq/terraform-aws-secure-baseline

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.

aws aws-auditing cis-benchmark devops hardening security security-hardening security-tools terraform terraform-module terraform-modules

Last synced: 11 Apr 2025

https://github.com/alichtman/stronghold

Easily configure macOS security settings from the terminal.

command-line command-line-tool hardening macos macos-setup osx security security-hardening

Last synced: 14 May 2025

https://github.com/graphenex/graphenex

Automated System Hardening Framework

hacktoberfest hardening hardening-commands security

Last synced: 02 Apr 2025

https://github.com/grapheneX/grapheneX

Automated System Hardening Framework

hacktoberfest hardening hardening-commands security

Last synced: 09 Jul 2025

https://github.com/step-security/harden-runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

actions egress-filtering github-actions hardening network-security runners runtime-security security-hardening supply-chain-security

Last synced: 13 May 2025

https://github.com/jvoisin/snuffleupagus

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

c elephant hardening php php-module php7 security security-hardening

Last synced: 15 May 2025

https://github.com/dev-sec/ansible-ssh-hardening

This Ansible role provides numerous security-related ssh configurations, providing all-round base protection.

ansible hardening playbook protection role ssh ssh-agent ssh-configuration ssh-hardening ssh-server

Last synced: 04 Oct 2025

https://github.com/DenizParlak/Zeus

AWS Auditing & Hardening Tool

aws aws-auditing aws-hardening cloudtrail hardening

Last synced: 23 Mar 2025

https://github.com/denizparlak/zeus

AWS Auditing & Hardening Tool

aws aws-auditing aws-hardening cloudtrail hardening

Last synced: 02 Apr 2025

https://github.com/dev-sec/cis-docker-benchmark

CIS Docker Benchmark - InSpec Profile

cis-docker-benchmark docker hardening inspec security

Last synced: 14 Mar 2025

https://github.com/dolevf/graphql-cop

Security Auditor Utility for GraphQL APIs

auditing blue-team graphql hacking hardening penetration-testing red-team security

Last synced: 15 May 2025

https://github.com/dev-sec/chef-os-hardening

This chef cookbook provides numerous security-related configurations, providing all-round base protection.

chef chef-cookbook devops hardening linux security

Last synced: 11 Aug 2025

https://github.com/lkrg-org/lkrg

Linux Kernel Runtime Guard

hardening integrity kernel linux security

Last synced: 13 Mar 2025

https://github.com/HardenedBSD/hardenedBSD

HardenedBSD implements strong exploit mitigations and security hardening technologies on top of FreeBSD, with a direct focus on the nexus between human rights and information security. HardenedBSD is the first (and only) enterprise operating system to have every part of its public infrastructure accessible by human-rights focused technologies like Tor Onion Services.

hardenedbsd hardening infosec operating-system security

Last synced: 13 May 2025

https://github.com/gildasio/h2t

h2t (HTTP Hardening Tool) scans a website and suggests security headers to apply

defense hardening headers http security web-application-security

Last synced: 14 Mar 2025

https://github.com/padok-team/yatas

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

account assessment audit aws best-practices cli cloud configuration devsecops gcp hardening security

Last synced: 16 May 2025

https://github.com/dev-sec/puppet-os-hardening

This puppet module provides numerous security-related configurations, providing all-round base protection.

hardening linux puppet security

Last synced: 23 Nov 2025

https://github.com/dev-sec/ssh-baseline

DevSec SSH Baseline - InSpec Profile

audit baseline devsec hacktoberfest hardening inspec security ssh

Last synced: 04 Jul 2025

https://github.com/finalduty/cis-benchmarks-audit

Simple command line tool to check for compliance against CIS Benchmarks

audit centos centos7 cis cis-benchmark compliance hardening

Last synced: 26 Mar 2025

https://github.com/alegrey91/systemd-service-hardening

Basic guide to harden systemd services

hardening linux security systemd

Last synced: 20 Aug 2025

https://github.com/k4yt3x/sysctl

K4YT3X's Hardened & Optimized Linux Kernel Parameters

hardening linux security sysctl

Last synced: 10 Apr 2025

https://github.com/troennes/private-secure-windows

Privacy and security baseline for personal Windows 10 and Windows 11

group-policy hardening privacy security security-hardening windows windows10 windows11

Last synced: 13 Jul 2025

https://github.com/jekil/hardentheworld

Harden the world is a community driven project to develop hardening guidelines and checklists for common software and devices.

hacking hardening hardening-steps secure-by-default security security-audit security-hardening sysadmin sysadmin-tasks

Last synced: 03 Jul 2025

https://github.com/dev-sec/ansible-nginx-hardening

This Ansible role provides secure nginx configurations.

ansible hardening nginx playbook protection role

Last synced: 09 May 2025

https://github.com/a449707101729771095/Windows-10-Hardening

An admittedly frivolous (and infrequently updated) attempt to harden Windows 10.

group-policy hardening office privacy registry windows-10

Last synced: 09 May 2025

https://github.com/klaver/sysctl

Linux/BSD kernel tuning and network security hardening optimizations, improving the performance of server systems via optimized sysctl tweaks

bsd-kernel-tuning centos debian fedora hardening ipv4 ipv6 kernel-tuning linux optimized-sysctl-tweaks performance redhat sysctl sysctl-variables tcp ubuntu udp

Last synced: 10 Apr 2025

https://github.com/simeononsecurity/standalone-windows-stig-script

Create a compliant and secure Windows 10/11 system with our Gold Master image creation tool. Adhere to DoD STIG/SRG Requirements and NSA Cybersecurity guidance for standalone Windows systems with ease, using our ultimate STIG script.

automation compliance cyber enterprise hardening hardware-requirements microsoft mil nsacyber powershell protection security security-hardening srgs-applied standalone-systems stig stigs windows windows10

Last synced: 11 May 2025

https://github.com/simeononsecurity/Standalone-Windows-STIG-Script

Create a compliant and secure Windows 10/11 system with our Gold Master image creation tool. Adhere to DoD STIG/SRG Requirements and NSA Cybersecurity guidance for standalone Windows systems with ease, using our ultimate STIG script.

automation compliance cyber enterprise hardening hardware-requirements microsoft mil nsacyber powershell protection security security-hardening srgs-applied standalone-systems stig stigs windows windows10

Last synced: 09 Apr 2025

https://github.com/dev-sec/cis-dil-benchmark

CIS Distribution Independent Linux Benchmark - InSpec Profile

audit baseline devsec hardening inspec linux security

Last synced: 16 May 2025

https://github.com/salesforce/metabadger

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).

automation aws cloud-security hardening metadata security

Last synced: 07 Apr 2025

https://github.com/dev-sec/ansible-mysql-hardening

This Ansible role provides security configuration for MySQL.

ansible database hardening mysql mysql-hardening playbook protection role security

Last synced: 09 May 2025

https://github.com/abdennour/certified-kubernetes-security-specialist

References for CKS Exam Objectives - Certified Kubernetes Security Specialist

certification cks ckss golang hardening kubernetes kubernetes-security security

Last synced: 16 Jun 2025

https://github.com/beerisgood/macos_hardening

a collection about macOS

apple arm hardening mac macos privacy security

Last synced: 05 Apr 2025

https://github.com/k4yt3x/sshd_config

K4YT3X's Hardened OpenSSH Server Configuration

hardening linux openssh security ssh

Last synced: 05 Apr 2025

https://github.com/ataumo/macos_hardening

This is a macOS hardening to read or set security configuration.

bash hardening macos macos-hardening macos-policies macos-scripting scripting

Last synced: 18 Apr 2025

https://github.com/risuorg/risu

Automation Troubleshooting Framework to validate and report configuration, software installed, etc with bash, python, and your language of choice.

automation bash compliance devops hacktoberfest hardening linux proactive python security-audit shell support troubleshooting

Last synced: 16 May 2025

https://github.com/CycodeLabs/cimon-action

Runtime Security Solution for your CI/CD Pipeline

cicd ebpf github-actions hardening linux security security-hardening supply-chain-security

Last synced: 11 May 2025

https://github.com/florianutz/ubuntu1604-cis

Ubuntu CIS Hardening Ansible Role

ansible ansible-role cis hardening ubuntu

Last synced: 19 Sep 2025

https://github.com/DenizParlak/hayat

Hayat is a script for report and analyze Google Cloud Platform resources.

cloud gcp gcp-cloud-functions gcp-hardening gcp-security hardening

Last synced: 11 May 2025

https://github.com/cycodelabs/cimon-action

Runtime Security Solution for your CI/CD Pipeline

cicd ebpf github-actions hardening linux security security-hardening supply-chain-security

Last synced: 01 Sep 2025

https://github.com/dev-sec/ssl-baseline

DevSec SSL/TLS Baseline - InSpec Profile

audit baseline devsec hardening inspec security ssl tls

Last synced: 04 Jul 2025

https://github.com/simeononsecurity/standalone-windows-server-stig-script

Enhance the security and compliance of your standalone Windows servers with our STIG script, specifically designed to meet DoD STIG/SRG requirements and NSACyber guidance. Achieve ultimate Windows Server protection with our easy-to-use script.

compliance cyber hardening hardware-requirements microsoft mil nsacyber security security-hardening srg srgs-applied stigs windows

Last synced: 10 Jun 2025

https://github.com/emirozer/nixarmor

nixarmor is a linux hardening automation project

hardening linux security shell

Last synced: 14 Oct 2025

https://github.com/simeononsecurity/Standalone-Windows-Server-STIG-Script

Enhance the security and compliance of your standalone Windows servers with our STIG script, specifically designed to meet DoD STIG/SRG requirements and NSACyber guidance. Achieve ultimate Windows Server protection with our easy-to-use script.

compliance cyber hardening hardware-requirements microsoft mil nsacyber security security-hardening srg srgs-applied stigs windows

Last synced: 06 May 2025

https://github.com/nozaq/amazon-linux-cis

Bootstrap script for Amazon Linux to comply CIS Amazon Linux Benchmark v2.0.0

amazon-linux aws cis hardening security

Last synced: 16 May 2025

https://github.com/dev-sec/postgres-baseline

DevSec PostgreSQL Baseline - InSpec Profile

audit baseline devsec hardening inspec postgresql security

Last synced: 04 Jul 2025

https://github.com/dev-sec/chef-nginx-hardening

This chef cookbook provides secure nginx configurations.

chef chef-cookbook devops hardening nginx security

Last synced: 04 Jul 2025

https://github.com/dev-sec/windows-patch-baseline

DevSec Windows Patch Baseline - InSpec Profile

audit baseline devsec hardening inspec patch security windows

Last synced: 10 Sep 2025

https://github.com/celenityy/Phoenix

Phoenix is a suite of configurations & advanced modifications for Mozilla Firefox, designed to put the user first - with a focus on privacy, security, freedom, & usability.

anti-tracking browser firefox firefox-based firefox-browser gecko hardened hardening mozilla mozilla-firefox privacy private secure security settings speed tracking user-js userjs web-browser

Last synced: 21 Feb 2025