Services Methodology Why Us About Us Blog Get in Touch
← Back to Device Configuration Reviews
// 07B — LINUX HARDENING

Linux Build
Review

Hardening assessment of Linux server and endpoint builds — RHEL, Ubuntu, Debian, FreeBSD and more — benchmarked against best security practices including CIS Linux benchmarks and DISA STIGs, covering kernel parameters, mandatory access control, and service configuration (SSH, SNMP, NFS, etc).

CIS benchmarksDISA STIGSELinux / AppArmorSSH HardeningKernel ParameterssystemdRHELUbuntuDebianAmazon Linux
Overview

Linux builds vary enormously between teams — and between the image that was hardened at build time and the box that's been running in production for three years. Package drift, disabled mandatory access controls, and permissive sudoers configuration accumulate quietly.

Our Linux build reviews assess server and endpoint builds against experience-guided misconfigurations and distribution-specific CIS benchmarks (Level 1 and Level 2) and DISA STIGs, covering filesystem integrity, mandatory access control coverage, network parameter hardening, and audit logging via auditd.

Findings are prioritised by exploitability for privilege escalation and lateral movement — the misconfigurations that matter once an attacker has a foothold, not just the ones a compliance scanner flags.

Testing Methodology
01

Scope & Baseline Selection

Identification of distribution, version, and role for each in-scope host, and selection of the matching CIS benchmark variant and STIG profile.

02

Configuration Data Collection

SSH-based, read-only collection of sysctl parameters, PAM configuration, SSHD settings, filesystem permissions, package inventory, and systemd unit state via a scoped service account.

03

Automated Benchmark Analysis

Automated assessment against security benchmarks covering filesystem integrity, mandatory access controls, network hardening, audit logging, and system security configuration.

04

Manual Review & Contextualisation

Manual review of SUID/SGID binaries, cron and systemd timer entries, sudoers configuration, SELinux/AppArmor enforcement mode and policy coverage, and container runtime exposure where applicable.

05

Risk Prioritisation

Findings ranked by exploitability for privilege escalation or lateral movement — world-writable directories, weak sudo rules, and exposed services surfaced ahead of low-impact compliance gaps.

06

Remediation Guidance

Custom guidance (including where appropriate, Ansible playbooks and shell remediation scripts) delivered alongside a prioritised fix list.

What Makes Levantis Different

We don’t just assess how systems were built. We assess how they’ve evolved — and where that evolution has introduced risk.

// In Scope

  • RHEL / CentOS / Rocky / AlmaLinux / Oracle Linux
  • Ubuntu Server & Desktop
  • Debian
  • Amazon Linux 2 / 2023
  • FreeBSD
  • Bare-metal container host OS (Docker/Kubernetes nodes)

// Standards

  • CIS benchmarks (distribution-specific, L1 & L2)
  • DISA STIGs
  • NCSC Linux guidance
  • Vendor hardening guides

// Typical Duration

  • Up to 2 builds: 3 days
  • 5+ builds: price on request

// Engage Us

Ready to scope an engagement? Get in touch for a no-obligation conversation.

Request Assessment

Know your Linux hardening gaps.

Configuration drift between golden image and production is where real exposure hides. Get a clear picture of where your builds actually stand.

Get in Touch