- Home
- Skills
- DevOps & Cloud
- server hardening
server hardening
Production-ready Linux security hardening for SSH, auditing, updates, and kernel networking.
Free
Works with the AI tools you already use
server hardening
Example session with this skill installed
Generate a production-ready SSH hardening configuration and an auditd ruleset to track root command execution.
- Read your context and instructions
- Compiled the server hardening
- Generated the document
I have generated the hardening configurations for SSH and system auditing. These follow the principle of least privilege and CIS best practices.
Production Server Hardening Configs
1. SSH Hardening (/etc/ssh/sshd_config.d/99-hardening.conf)
PermitRootLogin no
PasswordAuthentication no
ChallengeResponseAuthentication no
AllowAgentForwarding no
MaxAuthTries 3
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group16-sha512
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com
LogLevel VERBOSE
2. Auditd Rules (/etc/audit/rules.d/99-security.rules)
| Rule Type | Configuration | Description |
|---|---|---|
| Cleanup | -D | Flush existing rules |
| Buffer | -b 8192 | Increase buffer for high-log volume |
| Identity | -w /etc/shadow -p wa -k identity | Track changes to user credentials |
| PrivEsc | -a always,exit -F arch=b64 -S execve -F euid=0 -F auid>=1000 -k root_cmds | Log all commands run as root by users |
| Immutability | -e 2 | Lock configuration until next reboot |
Next steps
- Run
sshd -tto validate the SSH configuration before restarting the service. - Execute
augenrules --loadto apply the new audit policies. - Verify audit logging with
ausearch -k root_cmds.
server-hardening.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
The problem
Standard Linux server installations often ship with insecure defaults that leave systems vulnerable to automated brute-force attacks, rootkits, and lateral movement. Manually applying CIS Benchmarks across multiple configurations is error-prone and time-consuming.
What it does
- Configures automatic security updates with unattended-upgrades and needrestart for hands-off patching.
- Hardens SSH access by enforcing key-only auth, restricting users, and disabling weak cryptographic algorithms.
- Deploys auditd rulesets to track privilege escalation, file system changes, and suspicious system calls.
- Sets up PAM login policies including account lockout thresholds and strict password complexity requirements.
- Applies kernel-level network hardening via sysctl to mitigate spoofing and SYN flood attacks.
Frameworks & tools
Linux (Debian, Ubuntu, RHEL, CentOS), AppArmor, SELinux, auditd, PAM, rkhunter, and OpenSSH.
Why this beats prompting it yourself
Generic prompts often miss critical low-level details like PAM stack ordering or specific sysctl anti-spoofing flags. This skill provides production-ready configuration blocks and a 20-point checklist to ensure no hardening vector is overlooked.
Use cases
- Securing a fresh VPS or bare-metal server before deploying production workloads.
- Establishing an audit trail for compliance requirements like PCI-DSS or SOC2.
- Implementing Mandatory Access Control (MAC) profiles for high-risk web applications.
- Automating routine security maintenance like rootkit scanning and package patching.
Known limitations
Does not manage application-layer WAF rules, external network firewalls, or container-specific security profiles like Docker seccomp.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
1 install
Downloaded by developers to date
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 12 days ago
- Free to download with an account