iptables/netfilter firewall for Linux servers with stateful filtering, trust system, ipset block lists, SYN flood protection, VNET per-IP policies, and Docker support
-
Updated
May 22, 2026 - Shell
iptables/netfilter firewall for Linux servers with stateful filtering, trust system, ipset block lists, SYN flood protection, VNET per-IP policies, and Docker support
This script automates the scanning process using the OpenSCAP Security Guid to hardening Ubuntu systems, aligning with DISA-STIG compliance for Ubuntu 24.04. LTS minimum. It includes a range of security enhancements and configurations designed to strengthen the security posture of Ubuntu servers.
Lab-driven, dual-distro (CentOS Stream 10 / Debian 12) Linux Administration & Server Hardening course — 29 modules, 20 labs, 10 enterprise projects, RHCSA/LFCS-aligned.
Automated Linux environment initialization & post-installation setup script for Ubuntu/CentOS/RHEL. 支持开发环境一键配置、常用安全软件与 DevOps 工具链自动化安装、系统内核与网络参数深度性能优化和加固,世界杯备战
🧑💻 A comprehensive guide to Linux system administration, covering: 📜 Commands 👥 User Management 🌐 Networking 🔐 Permissions 📦 Package Management 💽 Disk Management 🛡️ Security 🤖 Automation ✅
Panduan lengkap memanfaatkan OCI Always Free Tier — provisioning ARM Ampere, Tailscale mesh VPN, hardening dengan Fail2ban, dan monitoring server
Idempotent VPS hardening for Ubuntu — SSH, firewall, fail2ban, kernel tuning, auditd, SOPS secrets, and optional AI agent workspace security. Dry-run first, lockout protection built in.
Bento turns a fresh Ubuntu/Debian VPS into a hardened Docker Swarm server with Traefik, Portainer, TLS, and deployable apps through a guided terminal menu.
Wazuh detection engineering, SIEM integrations, and SOC automation lab.
Automated, hardened OpenClaw setup for Ubuntu 24.04 VPS
An nftables configuration file with layer 7 filtering and DDoS protection for a Minecraft server. Includes rules for blocking fake sessions, query floods, and bot attacks, as well as filtering for IP addresses and port numbers.
Beginner-safe Linux VPS hardening skill for Claude Code. SSH lockdown deferred until key login is verified — first-time lockout structurally impossible. macOS/Linux/Windows laptops, Debian/Ubuntu servers.
Security hardening kit for OpenClaw servers. UFW firewall, fail2ban, Tailscale-only access, unattended upgrades, exposure verification.
Building a hardened Debian server from scratch: LVM over an encrypted volume, sudo policy, SSH, UFW and monitoring. The 42 Madrid write-up, with the reasoning.
Open-source CLI agent for automated Linux VPS security auditing. One command, 25 checks, zero install.
🛡️ Claude Code skill for automated Linux server hardening. 4 levels (minimal→paranoid), CIS/NIST/ANSSI compliant, 30+ security tools, smart service discovery. Type /hardening to secure your server.
🛡️ Autonomous AI Cybersecurity Log Analyst. An LLM-Agnostic SOC agent (Gemini, OpenAI, Claude, Local/Ollama) for Enterprise Linux Servers. Parses Apache, Nginx, MariaDB, and Journalctl logs. Features zero data egress, PII scrubbing, and auto-generated WAF (CSF) remediation with strict allowlisting.
🛡️ Lab-driven Linux Administration & Server Hardening — 29 modules, 20 labs, 10 enterprise projects (CentOS Stream 10 / Debian 12) | RHCSA/LFCS-aligned
WordPress security benchmark: prescriptive full-stack hardening controls for current supported WordPress releases on Linux.
To associate your repository with the server-hardening topic, visit your repo's landing page and select "manage topics."