Ship hardened Linux images without writing a single hardening script

Pick your distro, choose the CIS Benchmark controls you need, and we build, validate, and package a bootable image with an attached compliance report — ready for your servers, VMs, or airgapped environments.

1. Pick a base image

Ubuntu, Rocky Linux, Debian, or Fedora — server or workstation profile, any supported version.

2. Select your controls

Apply full CIS Level 1 or Level 2 profiles, or hand-pick individual controls to match your compliance scope.

3. Get a verified image

We remediate with Ansible, scan the result with OpenSCAP, and hand you an ISO or cloud image plus the compliance report.

Configure your image

Select your distribution, profile and CIS benchmark level to generate a custom hardened Linux image for your organization.

Profile
CIS Benchmark level
Extras

CIS Controls

Pick your benchmarks individually before submitting this order. The generated image will allow you to enable/disable most of the controls after the boot on its custom terminal control panel.

SelectIDTitleType
1.1.1.1Ensure cramfs kernel module is not availableAutomated
1.1.1.2Ensure freevxfs kernel module is not availableAutomated
1.1.1.3Ensure hfs kernel module is not availableAutomated
1.1.1.4Ensure hfsplus kernel module is not availableAutomated
1.1.1.5Ensure jffs2 kernel module is not availableAutomated
1.1.1.6Ensure squashfs kernel module is not availableAutomated
1.1.1.7Ensure udf kernel module is not availableAutomated
1.1.1.8Ensure usb-storage kernel module is not availableAutomated
1.1.2.1.1Ensure /tmp is a separate partitionAutomated
1.1.2.1.2Ensure nodev option set on /tmp partitionAutomated
1.1.2.1.3Ensure nosuid option set on /tmp partitionAutomated
1.1.2.1.4Ensure noexec option set on /tmp partitionAutomated
1.1.2.2.1Ensure /dev/shm is a separate partitionAutomated
1.1.2.2.2Ensure nodev option set on /dev/shm partitionAutomated
1.1.2.2.3Ensure nosuid option set on /dev/shm partitionAutomated
1.1.2.2.4Ensure noexec option set on /dev/shm partitionAutomated
1.1.2.3.1Ensure separate partition exists for /varAutomated
1.1.2.4.1Ensure separate partition exists for /var/tmpAutomated
1.1.2.4.2Ensure nodev option set on /var/tmp partitionAutomated
1.1.2.4.3Ensure nosuid option set on /var/tmp partitionAutomated
1.1.2.4.4Ensure noexec option set on /var/tmp partitionAutomated
1.1.2.5.1Ensure separate partition exists for /var/logAutomated
1.1.2.6.1Ensure separate partition exists for /var/log/auditAutomated
1.1.2.7.1Ensure separate partition exists for /homeAutomated
1.1.2.7.2Ensure nodev option set on /home partitionAutomated
1.2.1.1Ensure GPG keys are configuredAutomated
1.2.1.2Ensure package manager repositories are configuredAutomated
1.2.2.1Ensure updates, patches, and additional security software are installedAutomated
1.3.1.1Ensure AppArmor is installedAutomated
1.3.1.2Ensure AppArmor is enabled in the bootloader configurationAutomated
1.3.1.3Ensure all AppArmor Profiles are in enforce or complain modeAutomated
1.3.1.4Ensure all AppArmor Profiles are enforcingAutomated
1.4.1Ensure address space layout randomization (ASLR) is enabledAutomated
1.4.2Ensure ptrace_scope is restrictedAutomated
1.4.3Ensure core dump backtraces are disabledAutomated
1.4.4Ensure core dump storage is disabledAutomated
1.5.1Ensure XD/NX support is enabledManual
1.5.2Ensure prelink is not installedAutomated
1.5.3Ensure Automatic Error Reporting is not enabledAutomated
1.6.1Ensure message of the day is configured properlyAutomated
1.6.2Ensure local login warning banner is configured properlyAutomated
1.6.3Ensure remote login warning banner is configured properlyAutomated
1.6.4Ensure access to /etc/motd is configuredAutomated
1.6.5Ensure access to /etc/issue is configuredAutomated
1.6.6Ensure access to /etc/issue.net is configuredAutomated
1.7.1Ensure GNOME Display Manager is removedAutomated
1.7.2Ensure GDM login banner is configuredAutomated
1.7.10Ensure XDMCP is not enabledAutomated
2.1.1.1Ensure a single time synchronization daemon is in useAutomated
2.1.2.1Ensure systemd-timesyncd is configured with authorized timeserverAutomated
2.1.3.1Ensure chrony is configured with authorized timeserverAutomated
2.1.4.1Ensure ntp is configured with authorized timeserverAutomated
2.2.1Ensure autofs services are not in useAutomated
2.2.2Ensure avahi daemon services are not in useAutomated
2.2.3Ensure dhcp server services are not in useAutomated
2.2.4Ensure dns server services are not in useAutomated
2.2.5Ensure dnsmasq services are not in useAutomated
2.2.6Ensure samba file server services are not in useAutomated
2.2.7Ensure ftp server services are not in useAutomated
2.2.8Ensure message access server services are not in useAutomated
2.2.9Ensure network file system services are not in useAutomated
2.2.10Ensure nis server services are not in useAutomated
2.2.11Ensure print server services are not in useAutomated
2.2.12Ensure rpcbind services are not in useAutomated
2.2.13Ensure rsync services are not in useAutomated
2.2.14Ensure snmp services are not in useAutomated
2.2.15Ensure tftp server services are not in useAutomated
2.2.16Ensure web proxy server services are not in useAutomated
2.2.17Ensure web server services are not in useAutomated
2.2.18Ensure xinetd services are not in useAutomated
2.2.19Ensure X window server services are not in useAutomated
2.2.20Ensure mail transfer agent is configured for local-only modeAutomated
2.3.1Ensure NIS client is not installedAutomated
2.3.2Ensure rsh client is not installedAutomated
2.3.3Ensure talk client is not installedAutomated
2.3.4Ensure telnet client is not installedAutomated
2.3.5Ensure ldap client is not installedAutomated
2.3.6Ensure ftp client is not installedAutomated
3.1.1Ensure IPv6 status is identifiedManual
3.1.2Ensure wireless interfaces are disabledAutomated
3.1.3Ensure bluetooth services are not in useAutomated
3.2.1Ensure dccp kernel module is not availableAutomated
3.2.2Ensure tipc kernel module is not availableAutomated
3.2.3Ensure rds kernel module is not availableAutomated
3.2.4Ensure sctp kernel module is not availableAutomated
3.3.1Ensure ip forwarding is disabledAutomated
3.3.2Ensure packet redirect sending is disabledAutomated
3.3.3Ensure bogus icmp responses are ignoredAutomated
3.3.4Ensure broadcast icmp requests are ignoredAutomated
3.3.5Ensure icmp redirects are not acceptedAutomated
3.3.6Ensure secure icmp redirects are not acceptedAutomated
3.3.7Ensure reverse path filtering is enabledAutomated
3.3.8Ensure source routed packets are not acceptedAutomated
3.3.9Ensure suspicious packets are loggedAutomated
3.3.10Ensure tcp syn cookies is enabledAutomated
3.3.11Ensure ipv6 router advertisements are not acceptedAutomated
3.4.1.1Ensure ufw is installedAutomated
3.4.1.2Ensure iptables-persistent is not installed with ufwAutomated
3.4.1.3Ensure ufw service is enabledAutomated
3.4.1.4Ensure ufw loopback traffic is configuredAutomated
3.4.1.5Ensure ufw outbound connections are configuredManual
3.4.1.6Ensure ufw firewall rules exist for all open portsManual
3.4.1.7Ensure ufw default deny firewall policyAutomated
4.1.1.1Ensure systemd-journal-remote is installedAutomated
4.1.1.2Ensure systemd-journal-remote is configuredAutomated
4.1.1.3Ensure systemd-journal-upload authentication is configuredAutomated
4.1.1.4Ensure systemd-journal-remote service is enabledAutomated
4.1.1.5Ensure journald is not configured to receive logs from a remote clientAutomated
4.1.2.1Ensure journald service is enabled and activeAutomated
4.1.2.2Ensure journald log file access is configuredAutomated
4.1.2.3Ensure journald log file rotation is configuredAutomated
4.1.2.4Ensure only one logging system is in useAutomated
4.1.3.1Ensure rsyslog is installedAutomated
4.1.3.2Ensure rsyslog service is enabledAutomated
4.1.3.3Ensure journald is configured to send logs to rsyslogAutomated
4.1.3.4Ensure rsyslog log file creation mode is configuredAutomated
4.1.3.5Ensure rsyslog logging is configuredAutomated
4.1.3.6Ensure rsyslog is configured to send logs to a remote log hostAutomated
4.1.3.7Ensure logrotate is configuredAutomated
4.1.3.8Ensure all logfiles have appropriate access configuredAutomated
4.2.1.1Ensure auditd is installedAutomated
4.2.1.2Ensure auditd service is enabledAutomated
4.2.1.3Ensure auditing for processes that start prior to auditd is enabledAutomated
4.2.1.4Ensure audit_backlog_limit is sufficientAutomated
4.2.2.1Ensure audit log storage size is configuredAutomated
4.2.2.2Ensure audit logs are not automatically deletedAutomated
4.2.2.3Ensure system is disabled when audit logs are fullAutomated
4.2.2.4Ensure system warns when audit logs are low on spaceAutomated
4.2.3.1Ensure changes to system administration scope is collectedAutomated
4.2.3.2Ensure actions as another user are always loggedAutomated
4.2.3.3Ensure events that modify date and time information are collectedAutomated
4.2.3.4Ensure events that modify user/group information are collectedAutomated
4.2.3.5Ensure discretionary access control permission modification events are collectedAutomated
4.2.3.6Ensure unsuccessful unauthorized file access attempts are collectedAutomated
4.2.3.7Ensure events that modify the system's Mandatory Access Controls are collectedAutomated
4.2.3.8Ensure successful file system mounts are collectedAutomated
4.2.3.9Ensure session initiation information is collectedAutomated
4.2.3.10Ensure login and logout events are collectedAutomated
4.2.3.11Ensure file deletion events by users are collectedAutomated
4.2.3.12Ensure events that modify the sudo log file are collectedAutomated
4.2.3.13Ensure sudoers file changes are collectedAutomated
4.2.3.14Ensure system administrator command executions (sudo) are collectedAutomated
4.2.3.15Ensure kernel module loading unloading and modification is collectedAutomated
4.2.3.16Ensure the audit configuration is immutableAutomated
4.2.3.17Ensure the running and on disk configuration is the sameManual
4.2.4.1Ensure audit log files are mode 0640 or less permissiveAutomated
4.2.4.2Ensure only authorized users own audit log filesAutomated
4.2.4.3Ensure only authorized groups are assigned ownership of audit log filesAutomated
4.2.4.4Ensure the audit log directory is 0750 or more restrictiveAutomated
4.2.4.5Ensure audit configuration files are 640 or more restrictiveAutomated
4.2.4.6Ensure audit configuration files are owned by rootAutomated
4.2.4.7Ensure audit tools are 755 or more restrictiveAutomated
4.2.4.8Ensure audit tools are owned by rootAutomated
4.2.4.9Ensure cryptographic mechanisms are used to protect audit toolsAutomated
5.1.1Ensure cron daemon is enabled and activeAutomated
5.1.2Ensure permissions on /etc/crontab are configuredAutomated
5.1.3Ensure permissions on /etc/cron.hourly are configuredAutomated
5.1.4Ensure permissions on /etc/cron.daily are configuredAutomated
5.1.5Ensure permissions on /etc/cron.weekly are configuredAutomated
5.1.6Ensure permissions on /etc/cron.monthly are configuredAutomated
5.1.7Ensure permissions on /etc/cron.d are configuredAutomated
5.1.8Ensure cron is restricted to authorized usersAutomated
5.1.9Ensure at is restricted to authorized usersAutomated
5.2.1Ensure permissions on /etc/ssh/sshd_config are configuredAutomated
5.2.2Ensure permissions on SSH private host key files are configuredAutomated
5.2.3Ensure permissions on SSH public host key files are configuredAutomated
5.2.4Ensure sshd access is configuredAutomated
5.2.5Ensure sshd Banner is configuredAutomated
5.2.6Ensure sshd Ciphers are configuredAutomated
5.2.7Ensure sshd ClientAliveInterval and ClientAliveCountMax are configuredAutomated
5.2.8Ensure sshd DisableForwarding is enabledAutomated
5.2.9Ensure sshd GSSAPIAuthentication is disabledAutomated
5.2.10Ensure sshd HostbasedAuthentication is disabledAutomated
5.2.11Ensure sshd IgnoreRhosts is enabledAutomated
5.2.12Ensure sshd KexAlgorithms is configuredAutomated
5.2.13Ensure sshd LoginGraceTime is configuredAutomated
5.2.14Ensure sshd LogLevel is configuredAutomated
5.2.15Ensure sshd MACs are configuredAutomated
5.2.16Ensure sshd MaxAuthTries is configuredAutomated
5.2.17Ensure sshd MaxSessions is configuredAutomated
5.2.18Ensure sshd MaxStartups is configuredAutomated
5.2.19Ensure sshd PermitEmptyPasswords is disabledAutomated
5.2.20Ensure sshd PermitRootLogin is disabledAutomated
5.2.21Ensure sshd PermitUserEnvironment is disabledAutomated
5.2.22Ensure sshd UsePAM is enabledAutomated
5.3.1Ensure PAM software packages are up to dateAutomated
5.3.2Ensure pam_faillock module is enabledAutomated
5.3.3Ensure pam_pwquality module is enabledAutomated
5.3.4Ensure pam_pwhistory module is enabledAutomated
5.3.5Ensure password failed attempts lockout is configuredAutomated
5.3.6Ensure password unlock time is configuredAutomated
5.3.7Ensure password number of changed characters is configuredAutomated
5.3.8Ensure minimum password length is configuredAutomated
5.3.9Ensure password complexity is configuredAutomated
5.3.10Ensure password same consecutive characters is limitedAutomated
5.3.11Ensure password maximum sequential characters is configuredAutomated
5.3.12Ensure password dictionary check is enabledAutomated
5.3.13Ensure password quality checking is enforced for the root userAutomated
5.3.14Ensure password history remember is configuredAutomated
5.3.15Ensure password history is enforced for the root userAutomated
5.3.16Ensure pam_pwhistory includes use_authtokAutomated
5.3.17Ensure strong password hashing algorithm is configuredAutomated
5.4.1.1Ensure password expiration is configuredAutomated
5.4.1.2Ensure minimum password days is configuredAutomated
5.4.1.3Ensure password expiration warning days is configuredAutomated
5.4.1.4Ensure strong password hashing algorithm is configuredAutomated
5.4.1.5Ensure inactive password lock is configuredAutomated
5.4.1.6Ensure all users last password change date is in the pastManual
5.4.2.1Ensure root is the only UID 0 accountAutomated
5.4.2.2Ensure root is the only GID 0 accountAutomated
5.4.2.3Ensure group root is the only GID 0 groupAutomated
5.4.2.4Ensure root account access is controlledManual
5.4.2.5Ensure root path integrityAutomated
5.4.2.6Ensure root user umask is configuredAutomated
5.4.2.7Ensure system accounts do not have a valid login shellAutomated
5.4.2.8Ensure accounts without a valid login shell are lockedAutomated
5.4.3.1Ensure default group for the root account is GID 0Automated
5.4.3.2Ensure default user umask is configuredAutomated
5.4.3.3Ensure default user shell timeout is configuredAutomated
5.4.3.4Ensure nologin is not listed in /etc/shellsAutomated
6.1.1Ensure permissions on /etc/passwd are configuredAutomated
6.1.2Ensure permissions on /etc/passwd- are configuredAutomated
6.1.3Ensure permissions on /etc/group are configuredAutomated
6.1.4Ensure permissions on /etc/group- are configuredAutomated
6.1.5Ensure permissions on /etc/shadow are configuredAutomated
6.1.6Ensure permissions on /etc/shadow- are configuredAutomated
6.1.7Ensure permissions on /etc/gshadow are configuredAutomated
6.1.8Ensure permissions on /etc/gshadow- are configuredAutomated
6.1.9Ensure no world writable files existAutomated
6.1.10Ensure no unowned files or directories existAutomated
6.1.11Ensure no ungrouped files or directories existAutomated
6.1.12Ensure sticky bit is set on all world-writable directoriesAutomated
6.1.13Ensure suid and sgid files are reviewedManual
6.2.1Ensure accounts in /etc/passwd use shadowed passwordsAutomated
6.2.2Ensure /etc/shadow password fields are not emptyAutomated
6.2.3Ensure all groups in /etc/passwd exist in /etc/groupAutomated
6.2.4Ensure no duplicate UIDs existAutomated
6.2.5Ensure no duplicate GIDs existAutomated
6.2.6Ensure no duplicate user names existAutomated
6.2.7Ensure no duplicate group names existAutomated
6.2.8Ensure local interactive user home directories are configuredAutomated
6.2.9Ensure local interactive users own their home directoriesAutomated
6.2.10Ensure local interactive user home directories are mode 750 or more restrictiveAutomated
6.2.11Ensure no local interactive user has a .netrc, .forward or .rhosts fileAutomated
6.2.12Ensure local interactive user dot files access is configuredAutomated

Complete Order

Our sales team will contact you after your order is placed.

BOZKAROS

Your controls. Your image. Zero manual hardening.

A solution by Siperal.

© 2026BozkarosAll Rights Reserved.
🇹🇷  Made in Türkiye.