Linux Build
Review
Hardening assessment of Linux server and endpoint builds — RHEL, Ubuntu, Debian, FreeBSD and more — benchmarked against best security practices including CIS Linux benchmarks and DISA STIGs, covering kernel parameters, mandatory access control, and service configuration (SSH, SNMP, NFS, etc).
Linux builds vary enormously between teams — and between the image that was hardened at build time and the box that's been running in production for three years. Package drift, disabled mandatory access controls, and permissive sudoers configuration accumulate quietly.
Our Linux build reviews assess server and endpoint builds against experience-guided misconfigurations and distribution-specific CIS benchmarks (Level 1 and Level 2) and DISA STIGs, covering filesystem integrity, mandatory access control coverage, network parameter hardening, and audit logging via auditd.
Findings are prioritised by exploitability for privilege escalation and lateral movement — the misconfigurations that matter once an attacker has a foothold, not just the ones a compliance scanner flags.
Scope & Baseline Selection
Identification of distribution, version, and role for each in-scope host, and selection of the matching CIS benchmark variant and STIG profile.
Configuration Data Collection
SSH-based, read-only collection of sysctl parameters, PAM configuration, SSHD settings, filesystem permissions, package inventory, and systemd unit state via a scoped service account.
Automated Benchmark Analysis
Automated assessment against security benchmarks covering filesystem integrity, mandatory access controls, network hardening, audit logging, and system security configuration.
Manual Review & Contextualisation
Manual review of SUID/SGID binaries, cron and systemd timer entries, sudoers configuration, SELinux/AppArmor enforcement mode and policy coverage, and container runtime exposure where applicable.
Risk Prioritisation
Findings ranked by exploitability for privilege escalation or lateral movement — world-writable directories, weak sudo rules, and exposed services surfaced ahead of low-impact compliance gaps.
Remediation Guidance
Custom guidance (including where appropriate, Ansible playbooks and shell remediation scripts) delivered alongside a prioritised fix list.
We don’t just assess how systems were built. We assess how they’ve evolved — and where that evolution has introduced risk.