# Linux hardening privacy ratings

Tools that harden Linux systems.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [AppArmor](https://privacyratings.com/linux-hardening/apparmor/) | B (80/100) | Unknown | A Linux kernel security module that confines programs with per-application profiles restricting file access, network access and capabilities. It is enabled by default on Ubuntu and Debian. |
| [ClamTk](https://privacyratings.com/linux-hardening/clamtk/) | B (80/100) | Unknown | A graphical front end for the ClamAV antivirus engine that runs on-demand virus scans on Linux. The project is no longer maintained. |
| [Fail2Ban](https://privacyratings.com/linux-hardening/fail2ban/) | B (80/100) | Unknown | A daemon that scans log files for repeated failed logins and other abuse, and bans the offending IP addresses through firewall rules for a set time. |
| [Firejail](https://privacyratings.com/linux-hardening/firejail/) | B (80/100) | Unknown | Firejail is a SUID sandbox program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf. |
| [Lynis](https://privacyratings.com/linux-hardening/lynis/) | B (80/100) | Netherlands (Nine Eyes) | A command-line security auditing tool from CISOfy that scans Linux, macOS and other Unix-like systems and suggests hardening steps. |
| [Rootkit Hunter](https://privacyratings.com/linux-hardening/rkhunter/) | B (80/100) | Unknown | A shell-script scanner that checks Unix-like systems for rootkits, backdoors and local exploits by comparing file hashes and looking for suspicious files and settings. It has had no new release since version 1.4.6. |
| [Snort](https://privacyratings.com/linux-hardening/snort/) | B (80/100) | United States (Five Eyes) | Open source intrusion prevention system capable of real-time traffic analysis and packet logging. |
| [SysWarden](https://privacyratings.com/linux-hardening/syswarden/) | B (80/100) | Unknown | Open-source, host-local Linux security orchestrator combining nftables enforcement, system telemetry, threat-intelligence feeds, out-of-band WAAP log analysis and a terminal dashboard. |
| [USBGuard](https://privacyratings.com/linux-hardening/usbguard/) | B (80/100) | Unknown | A Linux daemon that blocks or allows USB devices based on a policy of device attributes, protecting against rogue USB devices such as BadUSB. |
| [CrowdSec](https://privacyratings.com/linux-hardening/crowdsec/) | F (35/100) | France (Nine Eyes) | An open source security engine that detects attacks in logs and blocks offending IP addresses, and shares signals with a crowdsourced blocklist run by the French company CrowdSec. |
| [BleachBit](https://privacyratings.com/linux-hardening/bleachbit/) | F (30/100) | Unknown | A disk cleaner that deletes caches, cookies, logs, temporary files and other traces left by applications, and can shred files and wipe free space. |
| [chkrootkit](https://privacyratings.com/linux-hardening/chkrootkit/) | F (30/100) | Unknown | A set of shell scripts and small programs that locally check a Unix-like system for signs of known rootkits. |
| [OpenSnitch](https://privacyratings.com/firewalls/opensnitch/) (rated under Firewalls) | B (80/100) | Unknown | Application firewall for Linux that shows outgoing connections from each program and lets users allow or deny them with per-app rules. |
| [Portmaster](https://privacyratings.com/firewalls/portmaster/) (rated under Firewalls) | B (80/100) | Austria | Application firewall for Windows and Linux that monitors and blocks network connections per app, with DNS filtering, tracker blocklists and an optional paid multi-hop network (SPN). |
| [Uncomplicated Firewall](https://privacyratings.com/firewalls/uncomplicated-firewall/) (rated under Firewalls) | B (80/100) | Unknown | Command-line front end for managing Netfilter firewall rules on Linux, the default firewall tool on Ubuntu, with simple commands for allowing and denying traffic. |
| [Gufw](https://privacyratings.com/firewalls/gufw/) (rated under Firewalls) | D (50/100) | Unknown | Graphical interface for ufw (Uncomplicated Firewall) on Linux, for managing firewall rules, profiles and per-application allow or deny rules. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?

Source: https://privacyratings.com/linux-hardening/
