-
Home | OpenSCAP portal
(open-scap.org)
tool
NIST-certified SCAP tooling to assess and enforce security baselines, with community hardening guides
-
GitHub - ComplianceAsCode/content: Security automation content in SCAP, Bash, Ansible, and other formats
(GitHub)
repo
SCAP/XCCDF/OVAL hardening profiles with generated Ansible and bash remediation for RHEL, Ubuntu, SLES
-
CIS Benchmarks®
(CIS)
reference
consensus hardening baselines for 25+ product families; free PDFs, tailoring needs paid membership
-
DISA STIGs
(cyber.mil)
reference
US DoD Security Technical Implementation Guides, free public downloads
-
AIDE - Advanced Intrusion Detection Environment
(aide.github.io)
tool
File and directory integrity checker: rule-built database of hashes, perms, ACLs, SELinux and xattrs
-
GitHub - SELinuxProject/selinux-notebook: The SELinux Notebook
(GitHub)
repo
book-length reference on SELinux policy, kernel components and userspace tools; free, HTML/PDF/EPUB
-
Home
(firewalld)
tool
zone-based dynamic firewall daemon separating runtime from permanent config, with a D-Bus API
-
Mozilla SSL Configuration Generator
(ssl-config.mozilla.org)
tool
generator of TLS cipher and protocol config for common web servers; now redirects to TLSRef Configurator
-
OWASP Modsecurity Project
(Modsecurity Project)
tool
cross-platform WAF module with a rules language, paired with OWASP CRS; open source
-
Initial Server Setup with Ubuntu
(digitalocean.com)
tutorial
First steps on a fresh Ubuntu server: non-root user, sudo, SSH access, firewall
-
How to Set Up SSH Keys on Ubuntu: A Comprehensive Guide
(digitalocean.com)
tutorial
Generating an SSH keypair and installing the public key for passwordless login
-
UFW Essentials: Common Firewall Rules and Commands for Linux Security
(digitalocean.com)
tutorial
UFW rule syntax and command reference: allow, deny, ports, services, logging
-
How To Protect SSH with Fail2Ban on Ubuntu 22.04
(digitalocean.com)
tutorial
Fail2ban jails that watch auth logs and ban repeated SSH login failures
-
LPIC-3 Exam 303 Objectives
(Linux Professional Institute (LPI))
reference
LPIC-3 303-300 Security exam objectives with weights: X.509 and PKI, crypto, hardening, access control
-
Security Essentials Exam 020 Objectives
(Linux Professional Institute (LPI))
reference
objectives and weightings for LPI exam 020-100, an entry-level digital self-defence security certificate
-
認定Kubernetesセキュリティスペシャリスト (CKS-JP)
(Linux Foundation - Education)
reference
CKS exam objectives and domain weights: cluster hardening, supply chain, runtime; paid hands-on
-
dnsdist Overview - dnsdist documentation
(dnsdist.org)
reference
DoS- and abuse-aware DNS load balancer, runtime console, Lua or YAML config, Prometheus metrics
-
Welcome to NTPsec
(ntpsec.org)
tool
Security-hardened fork of NTP Classic, audited and stripped down for high-assurance deployments
-
Community Documentation
(openvpn.net)
reference
Community Edition docs: setup, routing, ethernet bridging, hardening, key management, platform notes
-
Sidero Labs | Makers of Talos Linux and Omni
(Sidero Labs)
tool
immutable Kubernetes OS with no sshd, shell or package manager: read-only root, gRPC/mTLS API, ~50 binaries
-
Open Source Security Foundation – Linux Foundation Projects
(openssf.org)
organisation
Linux Foundation body coordinating OSS security best practices, free secure-coding courses and tooling
-
GitHub - jtesta/ssh-audit: SSH server & client security auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)
(GitHub)
repo
Python scanner grading key exchange, host key, cipher and MAC algorithms against hardening policies
-
about | Alpine Linux
(alpinelinux.org)
article
musl and BusyBox base sized for containers: apk packaging, OpenRC init, PIE-hardened userland
-
Qubes OS: A reasonably secure operating system
(Qubes OS)
tool
Compartmentalises work into Xen VMs, with Whonix for anonymity and room for a Windows guest
-
OPNsense® is an open source, feature rich firewall and routing platform, offering cutting-edge network protection. - OPNsense
(OPNsense)
tool
FreeBSD-based firewall/router platform: multi-WAN, IPsec/OpenVPN/WireGuard, CARP failover, NetFlow reporting
-
VeraCrypt - Free Open source disk encryption with strong security for the Paranoid
(veracrypt.io)
tool
TrueCrypt 7.1a successor with 200k-iteration KDF, hidden volumes and full system-partition setup
-
ClamAVNet
(clamav.net)
tool
Signature-based malware scanner with daemon, CLI tools and auto-updating definitions; mail-gateway staple
-
LibreWolf Browser
(librewolf.net)
tool
Firefox rebuild with telemetry and DRM stripped, uBlock Origin bundled and hardened defaults