git:20260710.2925510 to git:20260710.62afd0f

15 added, 15 removed. Audit B to A.

---
- title: "Audit Linux host hardening drift before exposing SSH or rolling to production"
+ name: "Audit Linux host hardening drift before exposing SSH or rolling to production"
+ slug: "audit-linux-host-hardening-drift-before-exposing-ssh-or-rolling-to-production"
description: "Uses Lynis to run an on-host security audit and turn the findings into a prioritized hardening checklist for an agent or operator. Invoke it when a machine is about to become internet-facing, after base image changes, or whenever you need a quick read on hardening drift instead of a generic vulnerability scan."
+ github_stars: 15505
verification: "security_reviewed"
source: "https://github.com/CISOfy/lynis"
author: "CISOfy"
publisher_type: "Company"
- category:
- - "Security & Verification"
- framework:
- - "Multi-Framework"
+ category: "Security & Verification"
+ framework: "Multi-Framework"
tool_ecosystem:
github_repo: "CISOfy/lynis"
github_stars: 15505
---
# Audit Linux host hardening drift before exposing SSH or rolling to production
Uses Lynis to run an on-host security audit and turn the findings into a prioritized hardening checklist for an agent or operator. Invoke it when a machine is about to become internet-facing, after base image changes, or whenever you need a quick read on hardening drift instead of a generic vulnerability scan.
## Prerequisites
Shell access to the target UNIX-like host, with root or sudo recommended for fuller audit coverage
## Installation
- Choose whichever fits your setup:
+ Use the upstream install or setup path that matches your environment:
+ - git clone https://github.com/CISOfy/lynis
- 1. Copy this skill folder into your local skills directory.
- 2. Clone the repo and symlink or copy the skill into your agent workspace.
- 3. Add the repo as a git submodule if you manage shared skills centrally.
- 4. Install it through your internal provisioning or packaging workflow.
- 5. Download the folder directly from GitHub and place it in your skills collection.
+ Requirements and caveats from upstream:
+ - Article by TechRepublic, considering Lynis a "must-have" tool: [How to quickly audit a Linux system from the command line](http://www.techrepublic.com/article/how-to-quickly-audit-a-linux-system-from-the-command-line/)
- Install command or upstream instructions:
+ Basic usage or getting-started notes:
+ - There are multiple options available to install Lynis.
+ - ### Software package
+ - For systems running Linux, BSD, and macOS, there is typically a package available. This is the preferred method of obtaining Lynis, as it is quick to install and easy to update. The Lynis project itself also provides...
- ```
- git clone https://github.com/CISOfy/lynis && cd lynis && ./lynis audit system
- ```
+ - Source: https://github.com/CISOfy/lynis
+ - Extracted from upstream docs: https://raw.githubusercontent.com/CISOfy/lynis/HEAD/README.md
## Documentation
- https://cisofy.com/documentation/lynis/
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/audit-linux-host-hardening-drift-before-exposing-ssh-or-rolling-to-production/)