Logo - By Henry
   Home | Projects | Articles | Security Net | Contributors | Contact | Wishlist  

Home » Projects » Lynis


Security and system auditing tool to harden Linux systems (and more)
Project information
Lynis is an auditing tool for Unix/Linux. It performs a security scan and determines the hardening state of the machine. Any detected security issues will be provided in the form of a suggestion or warning. Beside security related information it will also scan for general system information, installed packages and possible configuration errors.

This software aims in assisting automated auditing, hardening, software patch management, vulnerability and malware scanning of Unix/Linux based systems. It can be run without prior installation, so inclusion on read only storage is possible (USB stick, cd/dvd).

Lynis assists auditors in performing Basel II, GLBA, HIPAA, PCI DSS and SOx (Sarbanes-Oxley) compliance audits.

Intended audience:
Security specialists, penetration testers, system auditors, system/network managers.

Examples of audit tests:
- Available authentication methods
- Expired SSL certificates
- Outdated software
- User accounts without password
- Incorrect file permissions
- Configuration errors
- Firewall auditing

Current state:
Stable releases are available, development is active.

Background information:
Lynis is an audit script written in the common shell scripting language (sh). Therefore it runs on most systems without any adjustments. Packages are created by several maintainers, for easier installation. Still, if one would like to use the latest version, simply download the tarball, extract it to a temporary directory and run the tool.
System requirements:
- Compatible operating system (see 'Supported operating systems')
- Default shell

Supported operating systems
Tested on:
- Arch Linux
- CentOS
- Debian
- Fedora Core
- FreeBSD
- Gentoo
- Knoppix
- Linux Mint
- Mac OS X
- Mandriva
- OpenBSD
- OpenSolaris
- OpenSuSE
- Oracle Linux
- PCLinuxOS
- Red Hat Enterprise Linux (RHEL)
- Red Hat derivatives
- Slackware
- Solaris 10
- Ubuntu

Did it work on your operating system? Let me know!

Extra information

SHA1 hashes:
1.5.1 (SHA1): c6900ec339c8f59aa02321764d2284a402930361
1.5.0 (SHA1): 082c1ff1cac36af4548d5626d7dc4f0d263f8d11
1.4.9 (SHA1): 1861ae3828fb14601230559a5abbeb925662b409
1.4.8 (SHA1): 58c1c1916072fbeadc945f32f6b2a6ec7c900fb8
1.4.7 (SHA1): 2c38d0aef90dbe64839478f1f9fdfaec7346f40b
1.4.6 (SHA1): 7525887282accb95da7c4257050c7d1913782c38
1.4.5 (SHA1): c2586439b5d80652c86d44df87e3eb49a06dd31c
1.4.4 (SHA1): 54e68b60a305c13f5a6eda14626e6c80e1ea3b50
1.4.3 (SHA1): 7e73a94c0573e703e68f47963ed37e6747347f96

Project related documentation
- Lynis documentation

Tags: audit auditing security scan tool hardening

Page last updated at 25 Apr 2014

Quick links

Project members

Michael Boelen - Developer


- Lynis RPM (spec)
- Lynis packages (external)
- Non-official RPM's (by Peter Linnell)
- Debian package
- Fedora package
- Lynis Demo


- Standard output

Related links

- Documentation
- Changelog
- Project page/notification

Lynis Details
Latest version1.5.1
LanguageShell script
LicenseGPL v3

Lynis Enterprise Suite

This website is also part of our mission to help individuals and companies to secure their systems and comply with regulations. As such, this website is additional guide for the open source community and our users of the Lynis Enterprise Suite:

Complete solution to audit, harden and secure your Linux/Unix environment.

  • Perform audits within a few minutes
  • Central management
  • Powerful reporting
  • Additional plugins and more tests

Lynis Enterprise screenshot
Lynis Enterprise Screenshot: Output of a customized implementation plan

Tell me more »


"A master piece of software and a must for every server admin." - Jose

"Happy installing Lynis on every server I install. Also made some changes for automation and having regular scans of the system. For several customers I made some custom checks on integrity." - Rick Voormolen

» About

Thanks to
» Contributors
» Sponsors

Valid XHTML 1.0!

[PHPips enabled]
Copyright 2003-2019 and Michael Boelen, supported by CISOfy
All rights reserved
Hosted by Shock Media