Privacy Ratings

Open-source Linux hardening

11 Linux hardening whose code is public under an OSI-approved license, rated for privacy with evidence. Picks first, then by score.

  1. AppArmor Grade B

    A Linux kernel security module that confines programs with per-application profiles restricting file access, network access and capabilities. It is enabled by default on Ubuntu and Debian.

    GPL-2.0, with some libraries under other open source licenses. Source code

  2. ClamTk Grade B

    A graphical front end for the ClamAV antivirus engine that runs on-demand virus scans on Linux. The project is no longer maintained.

    Perl license (GPL-1.0 or later, or Artistic License). Source code

  3. Fail2Ban Grade B

    A daemon that scans log files for repeated failed logins and other abuse, and bans the offending IP addresses through firewall rules for a set time.

    GPL-2.0. Source code

  4. Firejail Grade B

    Firejail is a SUID sandbox program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf.

    GPL-2.0. Source code

  5. Lynis Grade B

    A command-line security auditing tool from CISOfy that scans Linux, macOS and other Unix-like systems and suggests hardening steps.

    GPL-3.0. Source code

  6. Rootkit Hunter Grade B

    A shell-script scanner that checks Unix-like systems for rootkits, backdoors and local exploits by comparing file hashes and looking for suspicious files and settings. It has had no new release since version 1.4.6.

    GPL-2.0. Source code

  7. Snort Grade B

    Open source intrusion prevention system capable of real-time traffic analysis and packet logging.

    GPL-3.0 and GPL-2.0. Source code

  8. SysWarden Grade B

    Open-source, host-local Linux security orchestrator combining nftables enforcement, system telemetry, threat-intelligence feeds, out-of-band WAAP log analysis and a terminal dashboard.

    GPL-3.0. Source code

  9. USBGuard Grade B

    A Linux daemon that blocks or allows USB devices based on a policy of device attributes, protecting against rogue USB devices such as BadUSB.

    GPL-2.0. Source code

  10. BleachBit Grade F

    A disk cleaner that deletes caches, cookies, logs, temporary files and other traces left by applications, and can shred files and wipe free space.

    GPL-3.0. Source code

  11. chkrootkit Grade F

    A set of shell scripts and small programs that locally check a Unix-like system for signs of known rootkits.

    BSD-2-Clause. Source code

Compare all 12 Linux hardening, open source or not.