A comprehensive security auditing and hardening toolkit for multiple operating systems. Features automated compliance checks and security assessment tools based on industry standards and official security guidelines.
Tested on 22.04 LTS (Jammy Jellyfish)
Version | Released | End of Standard Support | End of Ubuntu Pro Support | End of Legacy Support |
---|---|---|---|---|
22.04 LTS (Jammy Jellyfish) | Apr 2022 | Apr 2027 | Apr 2032 | Apr 2034 |
240328_CIS_Ubuntu Linux 22.04 LTS Benchmark v2.0.0
- Initail Setup
- (Initial Setup) 1.1.1.1 Ensure cramfs kernel module is not available (Automated)
Tested on XenServer release 8.4.0 (xenenterprise)
Product | Version | Language | NSC | EOS | EOM & EOL | Notes |
---|---|---|---|---|---|---|
XenServer | 8 | EN | 03-26-2024 | 06-03-2024 | 11-30-2028 | XenServer specific licence required |
- Account
- (Account) Default Account Check
- (Account) Root Privilege Account Detection
- (Account) Password File Permission Check
- (Account) Group File Permissions Check
- (Account) Password Policy Check
- (Account) System Account Shell Restriction Check
- (Account) SU Command Restriction Check
- File System
- (File System) UMASK Default Configuration Check
- (File System) XSConsole File Permission Check
- (File System) Profile File Permission Check
- (File System) Hosts File Permission Check
- (File System) Issue File Permission Check
- (File System) Dump Command SUID/SGID Permission Check
- (File System) Home Directory and Configuration Files Permission Check
- (File System) Crontab File Permission Check
- (File System) Root PATH Environment Variable Check
- (File System) Service File Permission Check
- Network and Major App
- (Network and Major App) Session Timeout Configuration Check
- (Network and Major App)
echo
(7) Service Status Check - (Network and Major App)
discard
(9) Service Status Check - (Network and Major App)
daytime
(13) Service Status Check - (Network and Major App)
chargen
(19) Service Status Check - (Network and Major App)
time
(37) Service Status Check - (Network and Major App)
tftp
(69) Service Status Check - (Network and Major App)
finger
(79) Service Status Check - (Network and Major App)
sftp
(115) Service Status Check - (Network and Major App) PAM and SSH Configuration Check for Root Remote Access Control
- Logging
- (Logging) Authpriv Log Configuration Check
- (Logging) UDP Syslog Transfer Port (514) Security Check
- (Logging) Audit Log File Permission Check
- (Logging) Failed Login Attempts Log (btmp) Permission Check
- (Logging) XenStore Access Log Permission Check
- (Logging) Secure Log File Permission Check