Linux Security Audit 2026:
Comprehensive Guide with Commands
Context: Linux is known to be secure — but a default installation is far from a hardened system. In 2025, 5,530 kernel CVEs were recorded, and 79% of Linux attacks used no malware: they exploited misconfigurations and poorly protected credentials.
This guide covers comprehensively what a user must check:
How to use this guide
Each tile in the navigation below corresponds to a security area. Click an item in the menu to display the associated commands, expected results, and explanations. Commands are directly copyable.
I. The 13 essential checks
Navigate between categories using the left menu. Each panel displays the commands to run and the expected result.
II. Secure application comparison
Recommended applications by category, compared according to current security and privacy criteria in 2026.
Web browser
| Browser | Telemetry | Verdict |
|---|---|---|
| LibreWolf | None | ✓ Recommended |
| Hardened Firefox | Disableable | ✓ Good |
| Ungoogled Chromium | None | ✓ Acceptable |
| Brave | Partial | ~ Mitigated |
| Chrome / Edge | Maximal | ✗ Discouraged |
Password manager
| Application | Storage | Verdict |
|---|---|---|
| KeePassXC | Local, encrypted | ✓ Recommended |
| Bitwarden | Self‑hostable | ✓ Very good |
| 1Password | Proprietary cloud | ~ Acceptable |
| LastPass | Cloud (breached 2022) | ✗ Avoid |
| Browser built‑in | Cloud sync | ✗ Insufficient |
Instant messaging
| Application | Encryption | Verdict |
|---|---|---|
| Signal | E2E (Signal protocol) | ✓ Recommended |
| Element / Matrix | E2E optional | ✓ Good |
| Telegram | E2E optional only | ~ Insufficient |
| E2E (but Meta) | ✗ Discouraged | |
| Discord | No E2E | ✗ Avoid |
VPN — protocols & reliability
| Solution | Protocol | Verdict |
|---|---|---|
| WireGuard | WireGuard | ✓ Self‑hosted |
| Mullvad | WireGuard | ✓ Verified no‑log |
| ProtonVPN | WireGuard | ✓ Good |
| NordVPN / ExpressVPN | WireGuard | ~ Mitigated |
| Browser VPN | Simple proxy | ✗ Marketing |
Audit and detection tools (2026)
| Tool | Type | Usage | 2026 Verdict |
|---|---|---|---|
| Lynis | Full audit | Hardening score, recommendations | ✓ Must‑have reference |
| CrowdSec | Collaborative banning | Modern Fail2ban replacement, behavioural analysis, 60x faster | ✓ 2026 standard |
| rkhunter | Rootkit scanner | On‑demand audit, daily cron | ✓ Essential |
| chkrootkit | Rootkit scanner | Complement to rkhunter | ✓ Good complement |
| ClamAV | Antivirus | File scanning, mail server | ✓ Useful (mail server) |
| Fail2ban | IP banning | Brute‑force SSH, services | ~ Obsolete (prefer CrowdSec) |
| Wazuh | SIEM / IDS | Continuous monitoring, correlation | ~ Advanced / enterprise |
| Falco | Runtime security | Behavioural detection (containers, kernel) – CNCF graduated project | ✓ Container standard |
| OpenSCAP | Compliance | CIS Benchmark / DISA STIG audit | ✓ Regulatory compliance |
III. Lynis score — the automated audit reference
Lynis is the reference tool to obtain a numeric hardening score. It covers in 5 to 10 minutes all the areas of this article and provides prioritised recommendations.
Interpreting the score and practical limitations
Reaching a score > 90 is theoretically possible, but exposes you to documented functional risks.
| Parameter | Risk | Recommendation |
|---|---|---|
kernel.modules_disabled=1 | Disables kernel modules → USB devices, some external drives become inoperable | Avoid on workstations |
PAM modifications (pam_faillock, pam_tally2) | Incorrect configuration → sudo lockout and admin lockout | Use libpam-pwquality and test before reboot |
Source: user feedback, February 2026
IV. 2026 standards: automation, runtime and collective intelligence
Security practices have evolved in 2026. Here are the three pillars that complement classic auditing.
1. CrowdSec: the modern successor to Fail2ban
CrowdSec has become the reference solution for protecting against brute‑force and malicious scans. Written in Go, it is up to 60 times faster than Fail2ban and incorporates collaborative intelligence: when an attacker is detected on one server in the CrowdSec network, the IP is automatically blocked on all other servers in real time.
| Criterion | CrowdSec (2026) | Fail2ban (legacy) |
|---|---|---|
| Performance | Go, up to 60× faster | Python, single‑threaded |
| Collaboration | Global threat intelligence network | None |
| IPv6 | Native | Partial support |
| Integrated WAF | Yes (HTTP bouncers) | No |
| Machine learning | Behavioural analysis | Static rules |
2. Falco – runtime security (CNCF graduated)
In 2026, Falco is the reference runtime security project in the cloud‑native ecosystem. It interfaces directly with the Linux kernel to detect anomalous behaviour in real time: unauthorised process execution, suspicious volume mounts, unexpected network connections, etc.
3. Automating hardening with Ansible (devsec.hardening)
The devsec.hardening collection (formerly ansible-hardening) has become the community reference for applying hardening compliant with CIS and STIG benchmarks. It is actively maintained and supports recent versions.
| Role | Function | Status |
|---|---|---|
os_hardening | sysctl, file permissions, removal of dangerous packages | Active |
ssh_hardening | Ed25519 keys, password disabling, root restriction | Active |
nginx_hardening | Secure default configuration | Active |
mysql_hardening | Permissions, passwords, TLS | Active |
4. CIS Benchmarks: the compliance standard
CIS Benchmarks have become the essential reference to objectively measure an OS’s security in 2026. More than 171 open source projects on GitHub allow you to audit these benchmarks automatically.
| Tool | Type | Recommended use |
|---|---|---|
| OpenSCAP | HTML/XCCDF audit | Regulatory compliance (PCI‑DSS, HIPAA) |
| Prowler | Multi‑cloud environment | AWS/Azure/GCP + Linux audit |
| Ansible CIS roles | Automation | Continuous application and verification |
- CrowdSec vs Fail2ban – official comparison (CrowdSec FAQ)
- Falco – CNCF graduated (March 2026)
- devsec.hardening – latest updates (March 2026)
- CIS Benchmark tools – 171 GitHub projects (January 2026)
Conclusion
devsec.hardening."Linux provides excellent security primitives — and then hands you the controls. What you do with them is entirely up to you."
Find our technical analyses on safeitexperts.com.
👥 Comments
Comment on this article