Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Security Hardening

Security Hardening

39 projects

Showing 36 of 39 projects

How-to-Secure-A-Linux-Server
How-to-Secure-A-Linux-Server

A comprehensive, evolving guide to hardening a Linux server with practical steps and security best practices.

#linux-server#server-hardening#self-hosted-security
Stars27.8k
Forks1.8k
Last commit3 months ago
DockerSlim
DockerSlimGo

SlimToolkit minifies and secures container images by up to 30x without requiring changes to your Dockerfile or workflow.

#hacktoberfest#devops#cicd
Stars23.3k
Forks833
Last commit11 days ago
wsargent
wsargent

A comprehensive cheat sheet for Docker commands, best practices, and security tips.

#deployment#command-reference#containerization
Stars22.5k
Forks4.6k
Last commit1 year ago
lynis
lynisShell

A security auditing and hardening tool for UNIX-based systems, performing in-depth scans and compliance testing.

#system-hardening#hipaa#unix
Stars15.7k
Forks1.6k
Last commit28 days ago
Prowler
ProwlerPython

An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.

#aws-security#infrastructure-security#multi-cloud
Stars14.0k
Forks2.2k
Last commit1 day ago
prowler
prowlerPython

An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.

#aws-security#infrastructure-security#multi-cloud
Stars14.0k
Forks2.2k
Last commit1 day ago
Nginx HTTP server boilerplate configs
Nginx HTTP server boilerplate configs

A collection of Nginx configuration files to improve server performance, security, and resource delivery.

#http-server#standard#devops
Stars11.6k
Forks1.5k
Last commit1 month ago
Bubblewrap
BubblewrapC

A low-level unprivileged sandboxing tool for Linux that creates container-like environments without requiring root privileges.

#setuid-tool#container-runtime#filesystem-isolation
Stars7.5k
Forks345
Last commit6 days ago
Awesome Security Hardening
Awesome Security Hardening

A curated collection of security hardening guides, best practices, checklists, benchmarks, and tools for various systems and services.

#infrastructure-security#windows-hardening#infosec
Stars6.4k
Forks657
Last commit1 month ago
ansible-os-hardening
ansible-os-hardeningJinja

An Ansible collection providing battle-tested security hardening for Linux, SSH, nginx, and MySQL.

#system-hardening#mysql-security#ssh-security
Stars5.4k
Forks827
Last commit11 days ago
c2rust
c2rustRust

A transpiler that migrates C99-compliant code to unsafe Rust, preserving functionality and enabling incremental refactoring.

#legacy-modernization#migration#compiler-tooling
Stars4.7k
Forks301
Last commit3 days ago
NsJail
NsJailC++

A lightweight Linux process isolation tool using namespaces, cgroups, rlimits, and seccomp-bpf syscall filters for enhanced security.

#container-security#linux-namespaces#resource-limits
Stars3.9k
Forks330
Last commit11 days ago
Secure Headers
Secure HeadersRuby

A Ruby gem for automatically applying security headers with safe defaults to protect web applications from common vulnerabilities.

#csp#web-security#rails-middleware
Stars3.2k
Forks249
Last commit5 days ago
HardenTools
HardenToolsGo

A Windows security tool that reduces the attack surface by disabling risky features in Windows, Office, Adobe Reader, and LibreOffice.

#microsoft-office#libreoffice#windows-security
Stars3.1k
Forks258
Last commit10 months ago
Linux auditd Detection Ruleset
Linux auditd Detection RulesetShell

A production-ready auditd configuration for Linux security monitoring that works out-of-the-box across major distributions.

#security-hardening#linux-security#auditd-configuration
Stars1.8k
Forks306
Last commit1 month ago
PlumHound
PlumHoundPython

A BloodHoundAD report engine that transforms Neo4J graph queries into actionable security reports for blue and purple teams.

#bloodhoundad#security-reporting#directory
Stars1.3k
Forks129
Last commit6 months ago
Bane
BaneGo

A custom AppArmor profile generator for Docker containers that simplifies security configuration.

#container-security#devops#docker-security
Stars1.2k
Forks91
Last commit5 years ago
bane
baneGo

A custom AppArmor profile generator for Docker containers that simplifies container security.

#container-security#devops#docker-security
Stars1.2k
Forks91
Last commit5 years ago
terraform-aws-secure-baseline
terraform-aws-secure-baselineHCL

A Terraform module to configure AWS accounts with a secure baseline aligned to CIS AWS Foundations and AWS Foundational Security Best Practices.

#cloudtrail#aws-security#aws-config
Stars1.2k
Forks377
Last commit1 year ago
Harden Runner GitHub Action
Harden Runner GitHub ActionTypeScript

A CI/CD security agent that monitors GitHub Actions runners for threats like network egress, file integrity, and process activity.

#supply-chain-security#actions#runners
Stars1.2k
Forks107
Last commit14 days ago
stronghold
strongholdPython

A command-line tool to securely configure macOS security and privacy settings with a single command.

#metadata-cleanup#system-hardening#privacy-tools
Stars1.2k
Forks260
Last commit1 year ago
Stronghold
StrongholdPython

A command-line tool to securely configure macOS security and privacy settings with a single command.

#metadata-cleanup#system-hardening#privacy-tools
Stars1.2k
Forks260
Last commit1 year ago
Antivmdetect
AntivmdetectPython

A script that generates VirtualBox templates to harden Windows VMs against malware detection.

#sandbox#powershell-automation#security-hardening
Stars771
Forks125
Last commit3 years ago
Applied-Crypto-Hardening
Applied-Crypto-HardeningTeX

A practical guide to configuring secure online communication and services using cryptography best practices.

#crypto-configuration#security-hardening#configuration-guide
Stars701
Forks97
Last commit4 years ago
PESecurity
PESecurityPowerShell

PowerShell module to check Windows binaries for security features like ASLR, DEP, SafeSEH, and Authenticode.

#windows-security#control-flow-guard#security-hardening
Stars664
Forks148
Last commit1 year ago
nix-bitcoin
nix-bitcoinNix

A collection of Nix packages and NixOS modules for securely deploying full-featured Bitcoin and Lightning nodes.

#nix-packages#node-management#nixops
Stars603
Forks138
Last commit19 days ago
Nginx common configuration - Universal config and snippets
Nginx common configuration - Universal config and snippetsDockerfile

A collection of production-ready Nginx configuration snippets, templates, and best practices for common web server setups.

#reverse-proxy#sandbox#configs
Stars585
Forks21
Last commit2 years ago
CIS Docker Benchmark
CIS Docker BenchmarkRuby

An InSpec compliance profile that automates security testing for Docker daemon and containers against CIS benchmarks.

#container-security#inspec#docker-security
Stars524
Forks119
Last commit3 years ago
quick-secure
quick-secureShell

A script to quickly harden UNIX/Linux system permissions and ownership for security compliance and standardization.

#system-hardening#docker-security#security-baseline
Stars425
Forks50
Last commit6 years ago
Awesome Kubernetes (K8s) Threat Detection
Awesome Kubernetes (K8s) Threat Detection

A curated list of resources for detecting threats and defending Kubernetes systems.

#container-security#cloud-native-security#security-hardening
Stars406
Forks43
Last commit2 years ago
rails-template(ackama)
rails-template(ackama)Ruby

A Rails application template preloaded with best practices for TDD, security, deployment, and developer productivity.

#template#application-boilerplate#rails-template
Stars380
Forks24
Last commit9 days ago
oci-seccomp-bpf-hook
oci-seccomp-bpf-hookGo

An OCI hook that traces container syscalls using eBPF to generate tailored seccomp security profiles.

#container-security#runtime-security#oci-hook
Stars348
Forks39
Last commit16 days ago
Artillery
Artillery

An open-source blue team tool that protects Linux and Windows operating systems through multiple security methods.

#windows-security#security-hardening#linux-security
Stars339
Forks301
Last commit5 years ago
ansible-relayor
ansible-relayorHTML

An Ansible role that automates the deployment and management of Tor relays with security features like offline master keys and Prometheus monitoring.

#prometheus-monitoring#self-hosted-networking#offline-keys
Stars257
Forks42
Last commit7 days ago
OpenSCAP
OpenSCAPShell

Tools for vulnerability scanning and compliance auditing of Docker containers and images using OpenSCAP.

#compliance-auditing#container-security#security-hardening
Stars241
Forks44
Last commit9 years ago
Scarus
ScarusC++

An OCI-compatible container engine designed specifically for running Linux containers on High Performance Computing (HPC) environments.

#scientific-computing#high-performance-computing#workload-manager-integration
Stars150
Forks11
Last commit1 year ago
Page 1 of 2Next

Related Tags

#Security14#Hardening10#Docker9#Linux Security8#Linux8#Devops7#Container Security7#Compliance6#Devsecops6#System Hardening5#Compliance Automation5#Security Tools5
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub