Lynis: Audit Your Linux VPS Security in Under 10 Minutes
Before deciding what to harden on a server, you need to know its current security state. That is the exact problem Lynis solves: an open-source security auditing scanner that evaluates dozens of system areas and gives you a prioritized list of recommendations, serving as the starting point for any VPS hardening plan.
1. What does Lynis check?
Lynis does not exploit vulnerabilities or make changes on its own: it is a read-only auditor. In a single run, it checks:
- SSH configuration (authentication methods, allowed ciphers,
PermitRootLogin). - Active firewall and configured rules.
- Outdated packages or packages with ended support.
- Weak permissions on critical files (
/etc/passwd,/etc/shadow,crontab). - Accounts with empty passwords or lax password policies.
- Kernel and
sysctlparameters related to network security. - Known malware and rootkits already installed on the system.
2. Installation
On Debian/Ubuntu, it is available directly from the repositories:
sudo apt update
sudo apt install lynis
To always have the latest version (Lynis is frequently updated with new checks), you can instead use CISOfy's official repository following their documentation, or clone the project from GitHub.
3. Running the audit
sudo lynis audit system
The scan takes between 1 and 3 minutes on a typical VPS. You will see output organized by categories (Boot and services, Kernel, Firewalls, SSH Support...) with notices in three levels: suggestions (SUGGESTION), warnings (WARNING), and informational findings.
4. Understanding the results: The Hardening Index
At the end of the report, Lynis calculates a Hardening Index (0-100) summarizing the overall hardening level of the server. It is not an absolute measure of "safe" or "unsafe" — a fresh VPS easily scores around 60-65 — but it is very useful for measuring progress between successive audits.
The full report, with details for every check, is saved to:
cat /var/log/lynis-report.dat
5. Prioritizing what to fix first
Not all suggestions have the same impact. Prioritize what actually reduces real-world risk:
- Authentication:
PermitRootLogin no, key-only SSH authentication, password policies. - Attack Surface: active firewall, unnecessary ports closed, unused services disabled.
- Patching: outdated packages or known CVEs.
- Fine-grained hardening:
sysctlparameters, specific file permissions, legal warning banners.
The first three groups cover the majority of real-world risk; the rest are incremental improvements.
6. Automating and repeating audits
A one-time audit only captures a single moment. It is best to repeat it after major configuration changes and compare the Hardening Index over time:
# Save each report with a timestamp for comparison
sudo lynis audit system --cronjob > /var/log/lynis-$(date +%F).log
7. From point-in-time audits to continuous vigilance
Lynis gives you a snapshot of your server at the moment you run it, but it won't warn you if someone opens a new port or disables the firewall by mistake tomorrow. That is where SecuryBlack steps in with the FerroSentry agent: continuous security auditing with centralized alerts when your VPS configuration drifts from what you expect.