# decalage2/awesome-security-hardening

A collection of awesome security hardening guides, tools and other resources

Repository: https://github.com/decalage2/awesome-security-hardening
Canonical: https://ross.abutalabs.com/products/awesome-security-hardening
License Family: other
Topics: awesome-list, security, security-hardening, security-tools, windows-hardening, cybersecurity, cyber-security, infosec, best-practices, cis-benchmarks, blueteam, blue-team, computer-security, linux-hardening
Last push: 2026-05-05T21:38:04+00:00

## Health v2 (maintenance only)
Score: 68/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 80, release rhythm 35, longevity 100
- inputs: {"age_days": 2683, "days_push": 120, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6526, forks 682 (observed 2026-08-28T04:09:44.917186+00:00)

## What it is
A curated awesome-list of security hardening guides, best practices, checklists, benchmarks, and tools covering Linux, Windows, macOS, network devices, containers, and cloud. It is a reference resource rather than software, actively maintained with community contributions.

## Use cases
- find security hardening guides for ubuntu servers
- harden windows machines with best practices
- get cis benchmark resources for linux
- harden docker and kubernetes deployments
- find tools to audit ssh and tls configuration
- learn how to secure web servers like apache and nginx

## When to choose
- you need a starting point for hardening operating systems, servers, or cloud infrastructure
- you want curated links to benchmarks, checklists, and audit tools
- you are a blue-team or sysadmin looking for best-practice references

## When to avoid
- you need an executable tool rather than a list of links
- you need vendor-specific step-by-step hardening automation out of the box
- you need general security topics beyond hardening, like pentesting or malware analysis

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, developer-tools, documentation
- domain: security, self-hosted, awesome-lists
- platform: windows, cloud
- tags: security-hardening, cis-benchmarks, best-practices, infosec, blue-team, curated-list, devops, linux, macos, docker, kubernetes

## Member repositories
- decalage2/awesome-security-hardening (main) score 68

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:44.917186+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:44:09.663510+00:00, confidence not recorded.
  - readme: https://github.com/decalage2/awesome-security-hardening (fetched 2026-08-28T04:09:44.917186+00:00, sha 1dab57ce1ca4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
