<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Linux Hardening — Blog</title>
    <link>https://linux-hardening.vercel.app/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Thu, 25 Jun 2026 18:49:39 GMT</lastBuildDate>
    <atom:link href="https://linux-hardening.vercel.app/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Audit Linux Hardening with Lynis, CIS &amp; OpenSCAP</title>
      <link>https://linux-hardening.vercel.app/en/blog/audit-with-lynis-cis</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/audit-with-lynis-cis</guid>
      <description>Measure Linux hardening with CIS Benchmarks, DISA STIG and ANSSI-BP-028 using Lynis and OpenSCAP, then automate and track remediation.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Intrusion Detection on Linux with AIDE and fail2ban</title>
      <link>https://linux-hardening.vercel.app/en/blog/aide-fail2ban-detection</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/aide-fail2ban-detection</guid>
      <description>Detect breaches early with file integrity monitoring (AIDE), brute-force protection (fail2ban), and rootkit scanners as part of defense in depth.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Boot &amp; Physical Security: GRUB, LUKS, Secure Boot</title>
      <link>https://linux-hardening.vercel.app/en/blog/boot-grub-luks-hardening</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/boot-grub-luks-hardening</guid>
      <description>Harden the Linux boot chain against console access, stolen disks and evil-maid attacks with GRUB passwords, LUKS encryption and Secure Boot.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Automatic Security Updates on Linux</title>
      <link>https://linux-hardening.vercel.app/en/blog/automatic-security-updates</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/automatic-security-updates</guid>
      <description>Keep Linux patched automatically with unattended-upgrades and dnf-automatic, trusted repositories, and a reduced package surface.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Auditd &amp; Journald: A Logging Baseline</title>
      <link>https://linux-hardening.vercel.app/en/blog/auditd-logging-baseline</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/auditd-logging-baseline</guid>
      <description>Build a tamper-resistant logging baseline on Linux with persistent journald, the auditd framework, sensitive-file watches, and off-host log shipping.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SELinux &amp; AppArmor: Confining Linux with MAC</title>
      <link>https://linux-hardening.vercel.app/en/blog/selinux-apparmor-confinement</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/selinux-apparmor-confinement</guid>
      <description>Add Mandatory Access Control to Linux with SELinux and AppArmor. Keep SELinux enforcing, read denials, and fix policy instead of disabling it.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Sandboxing systemd Services to Cut Attack Surface</title>
      <link>https://linux-hardening.vercel.app/en/blog/systemd-service-sandboxing</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/systemd-service-sandboxing</guid>
      <description>Enumerate, disable, score and sandbox systemd units with drop-ins to shrink the attack surface of every Linux service you run.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Filesystem &amp; Mount Hardening on Linux</title>
      <link>https://linux-hardening.vercel.app/en/blog/filesystem-mount-hardening</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/filesystem-mount-hardening</guid>
      <description>Harden Linux filesystems with nodev/nosuid/noexec mount options, audit SUID/SGID binaries, fix world-writable files, and tighten permissions on sensitive paths.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kernel Hardening with sysctl, Modules &amp; Lockdown</title>
      <link>https://linux-hardening.vercel.app/en/blog/kernel-sysctl-hardening</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/kernel-sysctl-hardening</guid>
      <description>Harden the Linux kernel with sysctl tunables, module blacklisting, and lockdown mode. Practical /etc/sysctl.d and modprobe.d examples with verification.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>nftables Firewall Baseline for Linux Servers</title>
      <link>https://linux-hardening.vercel.app/en/blog/nftables-firewall-baseline</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/nftables-firewall-baseline</guid>
      <description>Build a default-deny nftables firewall, harden network sysctls, and shrink your exposed service footprint on any Linux server.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Least-privilege accounts and sudo on Linux</title>
      <link>https://linux-hardening.vercel.app/en/blog/least-privilege-accounts</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/least-privilege-accounts</guid>
      <description>Enforce strong passwords, account lockout, password aging, secure sudo drop-ins and a tight umask to apply least privilege on Linux systems.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Harden SSH access on Linux</title>
      <link>https://linux-hardening.vercel.app/en/blog/harden-ssh-access</link>
      <guid isPermaLink="true">https://linux-hardening.vercel.app/en/blog/harden-ssh-access</guid>
      <description>Move SSH to key-only authentication, disable root login, and lock down sshd with a battle-tested configuration.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>