awesome-security-hardening
A collection of awesome security hardening guides, tools and other resources
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
General
Hardening Guide Collections
CIS Benchmarks
(registration required)
NSA Cybersecurity Resources for Cybersecurity Professionals
and NSA Cybersecurity publications
US DoD DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)
Harden the World
a collection of hardening guidelines for devices, applications and OSs (mostly Apple for now).
GNU/Linux
ANSSI - Configuration recommendations of a GNU/Linux system
version 2.0, 2022
CIS Benchmark for Distribution Independent Linux
2019, archived
trimstray - The Practical Linux Hardening Guide
practical step-by-step instructions for building your own hardened systems and services. Tested on CentOS 7 and RHEL 7.
trimstray - Linux Hardening Checklist
most important hardening rules for GNU/Linux systems (summarized version of The Practical Linux Hardening Guide)
How To Secure A Linux Server
for a single Linux server at home
Neo23x0/auditd
Best Practice Auditd Configuration
CIRCL TR-83 - Linux Boot Hardening HOWTO
How to secure the boot sequence of your Linux based distribution (2024)
GNU/Linux >Red Hat Enterprise Linux - RHEL
GNU/Linux >CentOS
GNU/Linux >SUSE
GNU/Linux >Ubuntu
Windows
BSI/ERNW - Configuration Recommendations for Hardening of Windows 10 Using Built-in Functionalities
(2021) - focused on Windows 10 LTSC 2019
Awesome Windows Domain Hardening
A curated list of awesome Security Hardening techniques for Windows
Microsoft recommended block rules
List of applications or files that can be used by an attacker to circumvent application whitelisting policies
NSA - AppLocker Guidance
Configuration guidance for implementing application whitelisting with AppLocker
NSA - Pass the Hash Guidance
Configuration guidance for implementing Pass-the-Hash mitigations (Archived)
NSA - BitLocker Guidance
Configuration guidance for implementing disk encryption with BitLocker
NSA - Event Forwarding Guidance
Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding
Windows Defense in Depth Strategies
work in progress
Endpoint Isolation with the Windows Firewall
based on Jessica Payne’s ‘Demystifying the Windows Firewall’ talk from Ignite 2016
ZeroSec - Paving The Way to DA
red teaming techniques and how to prevent them
macOS
Network Devices
NSA - Harden Network Devices
(PDF) - very short but good summary
Network Devices >Switches
Network Devices >Routers
Network Devices >IPv6
NSA - IPv6 Security Guidance
(Jan 2023)
Network Devices >Firewalls
Virtualization - VMware
VMware Security Hardening Guides
covers most VMware products and versions
DISA STIGs - Virtualisation
VMware vSphere 6.0 and 5
ENISA - Security aspects of virtualization
generic, high-level best practices for virtualization and containers (Feb 2017)
ANSSI - Recommandations de sécurité pour les architectures basées sur VMware vSphere ESXi
for VMware 5.5 (2016), in French
VMware - Protecting vSphere From Specialized Malware
(2022) - see also Mandiant - Bad VIB(E)s Part Two: Detection and Hardening within ESXi Hypervisors
Containers - Docker - Kubernetes
CIS Docker Benchmarks
registration required
Services >SSH
Positron Security SSH Hardening Guides
(2017-2018) - focused on crypto algorithms
stribika - Secure Secure Shell
(2015) - some algorithm recommendations might be slightly outdated
Applied Crypto Hardening: bettercrypto.org
handy reference on how to configure the most common services’ crypto settings (TLS/SSL, PGP, SSH and other cryptographic tools)
IETF - Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH) draft-ietf-curdle-ssh-kex-sha2-10
update to the recommended set of key exchange methods for use in the Secure Shell (SSH) protocol to meet evolving needs for stronger security. This document updates RFC 4250.
Gravitational - How to SSH Properly
how to configure SSH to use certificates and two-factor authentication
Services >TLS/SSL
ANSSI - Security Recommendations for TLS
2017, does not cover TLS 1.3
Qualys SSL Labs - SSL and TLS Deployment Best Practices
2017, does not cover TLS 1.3
RFC 7540 Appendix A TLS 1.2 Cipher Suite Black List
Hypertext Transfer Protocol Version 2.
Applied Crypto Hardening: bettercrypto.org
handy reference on how to configure the most common services’ crypto settings (TLS/SSL, PGP, SSH and other cryptographic tools)
Services >Web Servers
Jetty hardening
(2015)
Services >Mail Servers
MDaemon - 15 Best Practices for Protecting Your Email
Generic recommandations but based on MDaemon Security Gateway for Email Servers
Services >FTP Servers
JSCAPE - Guide for securing FTP
Generic recommandations but based on JSCAPE MFT Server
Services >Database Servers
Services >Active Directory
ANSSI CERT-FR - Active Directory Security Assessment Checklist
other version with changelog - 2022 (English and French versions)
Services >ADFS
Services >Kerberos
Services >LDAP
LDAP Authentication Best Practices
retrieved from web.archive.org
Services >DNS
Services >NTP
Services >NFS
Linux NFS-HOWTO - Security and NFS
a good overview of NFS security issues and some mitigations
NFSv4 without Kerberos and permissions
why NFSv4 without Kerberos does not provide security
Services >CUPS
Authentication - Passwords
OWASP Password Storage Cheat Sheet
The only way to slow down offline attacks is by carefully choosing hash algorithms that are as resource intensive as possible.
Hardware - CPU - BIOS - UEFI
ANSSI - Hardware security requirements for x86 platforms
recommendations for security features and configuration options applying to hardware devices (CPU, BIOS, UEFI, etc) (Nov 2019)
NSA - Hardware and Firmware Security Guidance
Guidance for the Spectre, Meltdown, Speculative Store Bypass, Rogue System Register Read, Lazy FP State Restore, Bounds Check Bypass Store, TLBleed, and L1TF/Foreshadow vulnerabilities as well as general hardware and firmware security guidance.
Cloud
asecure.cloud - Build a Secure Cloud
A free repository of customizable AWS security configurations and best practices
Tools to check security hardening
Chef InSpec
open-source testing framework by Chef that enables you to specify compliance, security, and other policy requirements. can run on Windows and many Linux distributions.
Tools to check security hardening >GNU/Linux
OpenSCAP Base
oscap command line tool
SCAP Workbench
GUI for oscap
Tiger - The Unix security audit and intrusion detection tool
(might be outdated)
otseca
Open source security auditing tool to search and dump system configuration. It allows you to generate reports in HTML or RAW-HTML formats.
SUDO_KILLER
A tool to identify sudo rules' misconfigurations and vulnerabilities within sudo
CIS Benchmarks Audit
bash script which performs tests against your CentOS system to give an indication of whether the running server may comply with the CIS v2.2.0 Benchmarks for CentOS (only CentOS 7 for now)
CIS Debian Hardening
Modular Debian 11/12/13 security hardening scripts based on CIS Benchmarks recommendations.
VPS Security Audit Script
A comprehensive Bash script for auditing the security and performance of your VPS (Virtual Private Server)
Tools to check security hardening >Windows
Microsoft Security Compliance Toolkit 1.0
set of tools that allows enterprise security administrators to download, analyze, test, edit, and store Microsoft-recommended security configuration baselines for Windows and other Microsoft products
Microsoft DSC Environment Analyzer (DSCEA)
simple implementation of PowerShell Desired State Configuration that uses the declarative nature of DSC to scan Windows OS based systems in an environment against a defined reference MOF file and generate compliance reports as to whether systems match the desired configuration
HardeningAuditor
Scripts for comparing Microsoft Windows compliance with the Australian ASD 1709 & Office 2016 Hardening Guides
PingCastle
Tool to check the security of Active Directory
MDE-AuditCheck
Tool to check that Windows audit settings are properly configured in the GPO for Microsoft Defender for Endpoint
Tools to check security hardening >Network Devices
Tools to check security hardening >TLS/SSL
Qualys SSL Labs - SSL and TLS Deployment Best Practices
2017, does not cover TLS 1.3
CryptoLyzer
Fast, flexible and comprehensive server cryptographic protocol (TLS, SSL, SSH, DNSSEC) and related setting (HTTP headers, DNS records) analyzer and fingerprint (JA3, HASSH tag) generator with Python API and CLI.
SSLyze
Fast and powerful SSL/TLS scanning library.
testssl.sh
Testing TLS/SSL encryption anywhere on any port
Tools to check security hardening >SSH
CryptoLyzer
Fast, flexible and comprehensive server cryptographic protocol (TLS, SSL, SSH, DNSSEC) and related setting (HTTP headers, DNS records) analyzer and fingerprint (JA3, HASSH tag) generator with Python API and CLI.
ssh-audit
SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)
Tools to check security hardening >Hardware - CPU - BIOS - UEFI
CHIPSEC: Platform Security Assessment Framework
framework for analyzing the security of PC platforms including hardware, system firmware (BIOS/UEFI), and platform components
chipsec-check
Tools to generate a Debian Linux distribution with chipsec to test hardware requirements
Tools to check security hardening >Docker
Docker Bench for Security
script that checks for dozens of common best-practices around deploying Docker containers in production, inspired by the CIS Docker Community Edition Benchmark v1.1.0.
Tools to check security hardening >Cloud
toniblyx/my-arsenal-of-aws-security-tools
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
Tools to check security hardening >DNS
IntoDNS.ai
Free DNS and email security scanner. Checks SPF, DKIM, DMARC, DNSSEC, BIMI, MTA-STS configuration and provides AI-powered fix suggestions.
Tools to apply security hardening
DevSec Hardening Framework
a framework to automate hardening of OS and applications, using Chef, Ansible and Puppet
Tools to apply security hardening >GNU/Linux
Linux Server Hardener
for Debian/Ubuntu (2019)
Bastille Linux
outdated
Tools to apply security hardening >Windows
Microsoft Security Compliance Toolkit 1.0
set of tools that allows enterprise security administrators to download, analyze, test, edit, and store Microsoft-recommended security configuration baselines for Windows and other Microsoft products
Hardentools
for Windows individual users (not corporate environments) at risk, who might want an extra level of security at the price of some usability.
Windows 10 Hardening
A collective resource of settings modifications (mostly opt-outs) that attempt to make Windows 10 as private and as secure as possible.
Disassembler0 Windows 10 Initial Setup Script
PowerShell script for automation of routine tasks done after fresh installations of Windows 10 / Server 2016 / Server 2019
Automated-AD-Setup
A PowerShell script that aims to have a fully configured domain built in under 10 minutes, but also apply security configuration and hardening
mackwage/windows_hardening.cmd
Script to perform some hardening of Windows 10
Windows 10/11 Hardening Script by ZephrFish
PowerShell script to harden Windows 10/11
Tools to apply security hardening >TLS/SSL
Tools to apply security hardening >Cloud
toniblyx/my-arsenal-of-aws-security-tools
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
Password Generators
Related lists in Platforms
See categoryAwesome Mac
jaywcjlove/awesome-mac
This project is dedicated to collecting high-quality macOS software and organizing them systematically by different categories for easy search and use.
Open Source Mac Os Apps
serhii-londar/open-source-mac-os-apps
🚀 Awesome list of open source applications for macOS. https://t.me/s/opensourcemacosapps
Awesome-Kubernetes
ramitsurana/awesome-kubernetes
A curated list for awesome kubernetes sources :ship::tada:
Awesome Nodejs
sindresorhus/awesome-nodejs
:zap: Delightful Node.js packages and resources [BECAUSE OF TOO MUCH SPAM AND LOW-QUALITY SUBMISSIONS, SUBMISSIONS ARE PAUSED TEMPORARILY]
Awesome Home Assistant
frenck/awesome-home-assistant
A curated list of amazingly awesome Home Assistant resources.
Awesome Ios
vsouza/awesome-ios
A curated list of awesome iOS ecosystem, including Objective-C and Swift Projects