Security and system auditing tool to harden Linux systems (and more)Project information
Lynis is an auditing tool for Unix/Linux. It performs a security scan and determines the hardening state of the machine. Any detected security issues will be provided in the form of a suggestion or warning. Beside security related information it will also scan for general system information, installed packages and possible configuration errors.System requirements:
This software aims in assisting automated auditing, hardening, software patch management, vulnerability and malware scanning of Unix/Linux based systems. It can be run without prior installation, so inclusion on read only storage is possible (USB stick, cd/dvd).
Lynis assists auditors in performing Basel II, GLBA, HIPAA, PCI DSS and SOx (Sarbanes-Oxley) compliance audits.
Security specialists, penetration testers, system auditors, system/network managers.
Examples of audit tests:
- Available authentication methods
- Expired SSL certificates
- Outdated software
- User accounts without password
- Incorrect file permissions
- Configuration errors
- Firewall auditing
Stable releases are available, development is active.
Lynis is an audit script written in the common shell scripting language (sh). Therefore it runs on most systems without any adjustments. Packages are created by several maintainers, for easier installation. Still, if one would like to use the latest version, simply download the tarball, extract it to a temporary directory and run the tool.
- Compatible operating system (see 'Supported operating systems')Supported operating systems
- Default shell
Tested on:Extra information
- Arch Linux
- Fedora Core
- Linux Mint
- Mac OS X
- Oracle Linux
- Red Hat Enterprise Linux (RHEL)
- Red Hat derivatives
- Solaris 10
Did it work on your operating system? Let me know!
Project related documentation
1.3.5 (SHA1): 0ed600d3c827a3a2ccc20936f93ed59e3896aeb7
1.3.5 (SHA1): 844d01c2d677effa05529314fac4b1d654f761cb
1.3.4 (SHA1): 2c7e6f895a5c5a9090075a537a3fafe44afc2cca
1.3.3 (SHA1): f2201012e19b4cecf5183fd9d7f3536b0f424db6
1.3.2 (SHA1): 9452711362ce333936734239e873d1b59bf5607b
1.3.1 (SHA1): 049085f649230613ff2624667ad639ccb27974e1
- Lynis documentation
Tags: audit auditing security scan tool hardening
Page last updated at 03 Dec 2013
Michael Boelen - Developer
- Lynis RPM (spec)
- Lynis packages (external)
- Non-official RPM's (by Peter Linnell)
- Debian package
- Fedora package
- Lynis Demo
- Standard output
- Project page/notification