Lynis
Security auditing, system hardening, and compliance monitoring·cisofy.com
Lynis is a free and open source security auditing tool for Linux, macOS, BSD and other Unix-based systems that performs in-depth host scans to find vulnerabilities, misconfigurations, and compliance gaps. It requires no mandatory installation and can run with optional dependencies. Lynis Enterprise extends the open source tool with a SaaS or self-hosted platform offering a dashboard, reporting, hardening advice, intrusion detection, configuration management, and an API for continuous auditing in company environments.
What it's for
Features 15
- Central administration dashboard
- Compliance testing (PCI, HIPAA, SOx and others)
- Configuration management and change detection
- Continuous monitoring and auditing
- Customized action plans with priority-based hardening
- Different levels of user access
- In-depth host-based security scanning
- Intrusion detection via heuristics and anomalies
- Optional installation and dependencies
- Passive vulnerability scanning
- Plugin extensibility
- Programming Interface (API)
- Reporting and data export
- Support for all Unix, Linux, BSD and macOS versions
- System hardening recommendations with ready-to-use code snippets
At a glance
Complianceself-reported
Resources
Pricing
Lynis Enterprise SaaS is priced at $3 per system per month with a minimum of 5 systems; subscriptions run for one year with no auto-renewal. Self-hosted Enterprise and large-scale/custom deployments require a quote.
Open source command-line auditing tool
Community version, install via package, tarball, or GitHub
For companies; hosted as SaaS
Priced per system, minimum 5 systems; subscription runs for one year with no auto-renewal
Request a quote; volume discounts available
Quote-based; for companies with more than 100 systems, MSPs, or those needing self-hosted deployment
Volume discount available for self-hosted Enterprise customers with special needs or more than 100 systems