One command to harden Ubuntu — kernel to firewall, CIS-aligned, production-tested.
Hardening a server properly means touching SSH, the kernel, auditd, AppArmor, the firewall, time sync, malware scanning, and a dozen other subsystems — and getting any of them wrong can lock you out or break production. These scripts do all of it in one run, with safety checks, automatic backups, and a full report of every change.
git clone https://github.com/gensecaihq/Ubuntu-Security-Hardening-Script.git
cd Ubuntu-Security-Hardening-Script
sudo ./ubuntu-hardening-26-04.sh # pick the script for your Ubuntu version⭐ If this saves you an afternoon of hardening work, star the repo — it helps others find it.
- Complete — 17 hardening modules covering SSH, kernel sysctls, auditd, AppArmor, UFW, Fail2ban, AIDE, ClamAV, rootkit detection, automatic updates, systemd sandboxing, cloud metadata protection, and compliance scanning
- Safe by design — checks for SSH keys before disabling password auth, backs up every file it touches (with permissions), desktop detection prevents breaking GUI apps, and everything is logged
- Current — Ubuntu 26.04 LTS support with post-quantum SSH (ML-KEM), sudo-rs and Rust coreutils awareness, AppArmor 5.0, auditd 4.1
- Auditable — plain Bash you can read, a human report plus a JSON compliance report for your SIEM, and an OpenSCAP/Lynis baseline on completion
- Battle-tested — community-reported issues fixed across all scripts, plus a 2026 deep audit (v5.0) that eliminated SSH-lockout edge cases, made re-runs idempotent (no firewall-rule wipes, no duplicate configs), and removed a config that could open an unintended network listener
- Safe to re-run (v5.0 script) — running it again on an already-hardened box preserves your custom firewall rules and doesn't duplicate configuration
| Your Ubuntu | Script | Status |
|---|---|---|
| 26.04 LTS (supported to 2031) | ubuntu-hardening-26-04.sh v5.0 |
✅ Recommended |
| 24.04 LTS | ubuntu-hardening-24-04.sh v3.0 |
✅ Supported |
| 22.04 / 20.04 / 18.04 | ubuntu-hardening-original.sh v2.0 |
✅ Supported¹ |
| 25.04 / 25.10 | ubuntu-hardening-25.sh v4.0 |
⛔ EOL — upgrade to 26.04 |
¹ 20.04/18.04 standard support has ended — they need Ubuntu Pro ESM for security updates.
Access — SSH key-only auth with lockout prevention, root login disabled, post-quantum key exchange (26.04), PAM password quality, FIDO2 support Network — UFW default-deny with rate-limited SSH, SYN-flood/redirect/spoofing protection, cloud IMDS lockdown (AWS/Azure/GCP) Kernel — 40+ sysctl hardening keys, kernel lockdown, restricted eBPF/io_uring/ptrace, unprivileged userns restrictions Integrity — AIDE file monitoring, comprehensive auditd rules with Living-Off-The-Land and container-escape detection Malware — ClamAV with quarantine, rkhunter, chkrootkit, scheduled scans Compliance — OpenSCAP CIS/DISA-STIG scanning, Lynis audit, JSON report for SIEM
Full details: docs/security-controls.md
Built for the biggest Ubuntu security shift in years:
- 🔮 Post-quantum SSH — hybrid
mlkem768x25519-sha256key exchange (OpenSSH 10.2 / FIPS 203) - 🦀 Memory-safe defaults — sudo-rs and Rust coreutils detected and handled
- 🛡️ AppArmor 5.0 — user-namespace and io_uring mediation
- 🔐 TPM-backed FDE detection, Intel TDX + AMD SEV-SNP confidential computing
- 🤖 CI-friendly — fully non-interactive mode with safe defaults
Details and migration gotchas (DSA keys, sudo-rs, cgroup v1 removal): docs/ubuntu-26-04.md
| Guide | What's in it |
|---|---|
| Installation | Requirements, pre-flight checklist, CI usage, verification |
| Security Controls | Every control applied, script comparison matrix |
| Configuration | Firewall rules, SSH tweaks, Ubuntu Pro, AIDE/audit maintenance |
| Monitoring | Reports, log locations, routine commands, cadence |
| Troubleshooting | SSH lockout recovery, service failures, rollbacks |
| Compliance | OpenSCAP, CIS/DISA-STIG profiles, usg, SIEM integration |
| Ubuntu 26.04 Notes | What changed in 26.04 and how the script handles it |
- Snapshot first. These scripts change a lot of system state.
- SSH keys working? Password auth gets disabled (the script checks and warns if no keys are found).
- Console access ready? Only rate-limited SSH is allowed through the firewall afterward.
- Test in a VM before production. Review the report at
/var/log/security-hardening/.
Bug reports, fixes, and testing on different Ubuntu versions are all hugely welcome — see CONTRIBUTING.md. Look for good first issue to get started.
Found a security issue? Please report it privately — see SECURITY.md.
We're grateful to everyone who has contributed to making this project better! This includes opening issues, submitting pull requests, writing code, and participating in discussions.
|
BoozeLee 📖 |
Kingcitaldo125 🐛 |
MoezLog 🐛 |
Shekhar0050M 🐛 |
|
actions-user 💻 |
alokemajumder 💻 🐛 📖 |
benj-ntu 🐛 |
coderabbitai[bot] 💬 |
|
cropduster32 🐛 |
gainskills 📖 |
gensecai-dev 💻 |
Legend: 💻 Code | 🐛 Bug Reports | 📖 Documentation | 🚧 Maintenance | 💬 Discussions | 👀 Reviews
Note: This section is automatically updated when new contributors join the project.
MIT — see LICENSE.
Provided "AS IS" without warranty. These scripts make significant system changes: back up first, test in a non-production environment, review the code before running. The authors are not responsible for damage, data loss, or service interruption.
Version 5.0 · Updated August 8, 2026 · Supports Ubuntu 18.04 → 26.04 LTS · Issues · Discussions