Skip Navigation

What to use for system hardening

Im using linux for +-3 yrs and im pretty used to it. Im currently running nixos on my laptop. My question is what kind of hardening do i need firejail, apparmor, selinux, .. all 3 of them ? none of them ? Thanks for the advice and have a nice day

20 comments
  • You can use Lynis to scan your system for settings or weird behavior, it's pretty useful, some stuff don't have great explainations however... so you will need to do a bit of research to know why a certain setting should be turn off or stuff like that

    https://cisofy.com/lynis/

  • You're off to a good start, I'd recommend reading through and following this guide, its the best resource out there at the moment for Linux hardening/security imo.

  • Start with lynis and go from there. Also lsof -ni and disable things that you don't need.

    Lynis will help you to comply with cis benchmarks, which are another thing you should read through.

20 comments