Privacy Ratings

Linux hardening tool ratings

Tools that harden Linux systems.

16 Linux hardening are rated against 4 public criteria, and 16 have enough evidence for a letter grade. Of the 4 with a known jurisdiction, 1 is based in a Five Eyes country, and 3 in the wider Fourteen Eyes.

Open-source Linux hardening only · Criteria for this category · Suggest an addition · Markdown

16 shown
Linux hardening privacy ratings, sorted by pick and then by grade
Name Grade Score Data Jurisdiction Open sourceNo trackers or telemetryNo ads or data salesIndependent audit
A Linux kernel security module that confines programs with per-application profiles restricting file access, network access and capabilities. It is enabled by default on Ubuntu and Debian.
Grade B 80 100% – YesYesYesNo
A graphical front end for the ClamAV antivirus engine that runs on-demand virus scans on Linux. The project is no longer maintained.
Grade B 80 100% – YesYesYesNo
A daemon that scans log files for repeated failed logins and other abuse, and bans the offending IP addresses through firewall rules for a set time.
Grade B 80 100% – YesYesYesNo
Firejail is a SUID sandbox program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf.
Grade B 80 100% – YesYesYesNo
A command-line security auditing tool from CISOfy that scans Linux, macOS and other Unix-like systems and suggests hardening steps.
Grade B 80 100% Netherlands Nine Eyes YesYesYesNo
A shell-script scanner that checks Unix-like systems for rootkits, backdoors and local exploits by comparing file hashes and looking for suspicious files and settings. It has had no new release since version 1.4.6.
Grade B 80 100% – YesYesYesNo
Open source intrusion prevention system capable of real-time traffic analysis and packet logging.
Grade B 80 100% United States Five Eyes YesYesYesNo
Open-source, host-local Linux security orchestrator combining nftables enforcement, system telemetry, threat-intelligence feeds, out-of-band WAAP log analysis and a terminal dashboard.
Grade B 80 100% – YesYesYesNo
A Linux daemon that blocks or allows USB devices based on a policy of device attributes, protecting against rogue USB devices such as BadUSB.
Grade B 80 100% – YesYesYesNo
An open source security engine that detects attacks in logs and blocks offending IP addresses, and shares signals with a crowdsourced blocklist run by the French company CrowdSec.
Grade F 35 100% France Nine Eyes PartialNoYesNo
A disk cleaner that deletes caches, cookies, logs, temporary files and other traces left by applications, and can shred files and wipe free space.
Grade F 30 100% – YesNoNoNo
A set of shell scripts and small programs that locally check a Unix-like system for signs of known rootkits.
Grade F 30 100% – YesNoNoNo
OpenSnitch Firewalls
Application firewall for Linux that shows outgoing connections from each program and lets users allow or deny them with per-app rules.
Grade B 80 100% – YesYesYesNo
Portmaster Firewalls
Application firewall for Windows and Linux that monitors and blocks network connections per app, with DNS filtering, tracker blocklists and an optional paid multi-hop network (SPN).
Grade B 80 100% Austria Outside Eyes YesYesYesNo
Command-line front end for managing Netfilter firewall rules on Linux, the default firewall tool on Ubuntu, with simple commands for allowing and denying traffic.
Grade B 80 100% – YesYesYesNo
Gufw Firewalls
Graphical interface for ufw (Uncomplicated Firewall) on Linux, for managing firewall rules, profiles and per-application allow or deny rules.
Grade D 50 100% – YesNoYesNo

Questions

What is the most private option among Linux hardening?

No pick has been made yet. The table above is sorted by score, based on public evidence.

How are Linux hardening rated?

Each entry answers 4 questions: open source, no trackers or telemetry, no ads or data sales and independent audit. Answers need links to evidence. See the full criteria.

Does jurisdiction matter?

Jurisdiction decides which laws can compel a provider to hand over data. Each entry shows its country and whether it is in the Five, Nine or Fourteen Eyes. The data a provider can hand over depends mostly on what it stores and who holds the keys. Read about jurisdictions and the CLOUD Act.