Lynis – Security Auditing Tool for Linux, MacOS, and Unix-Based Systems
github.com
github.com
Surely a lot of this stuff can be automated. The simpler the tool the better - a single binary would be great. Is this a pipe dream?
edit: I feel like part of the problem would be shipping all the exploits. Legal matters aside, it would at the very least mean having to code exploits for thousands/millions of things. Though, perhaps a pluggable/linkable framework for this security could be a sort of proof of work. Ie, whitehats could publish the exploits by writing the plugin.
edit2: I'm aware that this tool is sort of what i'm talking about, but this mainly focuses on a single unix machine, right? Nor does it support windows. I wonder why we can't just make this ultimately simple? Ie, single binary?
[1]: Well, i know enough to know how little i know.. which is nearly nothing heh.
Besides, virus scanners are heavy and ugly, i've always hated them. Sure, it's nice to have monitoring of a breech, but why do i have to sit with holes in my security waiting for a breech? Some virus scanners try to monitor downloaded files or weird behavior etc, but i'd much rather scan my computer for holes, than things that have already exploited the security vulnerabilities that i had open.
To scan remote hosts, they simple need a single package installed (I think they actually only need the oscap binary) and an SSH server running.
In recent versions of Anaconda, you can specify a security policy in your kickstart file and have the host configured in accordance with the security policy as part of the installation process. The host is in compliance before you even get that first initial "login" prompt. (For those of us who have to deal with this, this is f'ing awesome.)
Another thing you can do with it is compare a host against, say, Red Hat's security errata and get a report of which security updates a host is missing. This can be automated, ran by cron, and the results e-mailed to you once a week or whatever.
All that said, OpenSCAP isn't a panacea. It's still pretty "rough around the edges", so to speak, but it's much, much better than the tools we had to deal with this stuff just two or three years ago.
Windows isn't a supported platform (yet). There's still a lot of work to do on the Linux side of things to improve the software so I'm not sure when (if?) they'll start working at Windows.
[0]: https://www.open-scap.org/
[1]: https://www.open-scap.org/security-policies/scap-security-gu...
I tried it a few months ago and as far as I could see, it's not just Windows that is unsupported, it only really supports Red Hat. It was packaged for Debian, but the policy files were absent and you could only find old unmaintained ones.
(this is not a critic, I understand that Red Hat prefers to spend money on their own distro)
Do people actually use it though?
Also consider the cost of dealing with the data falling into the wrong hands. Even data that is not personal can hurt you financially in the long-term.
The cost of running security tools is minimal when you take it all into account.
I think there may be some cases where you don't feel comfortable automating the full remediation, e.g., requires reboot, so separate audit system might be useful. There is also something nice about writing your audit rules, being able to show auditors "this is what we check for", and then running that across your infrastructure. In that case InSpec (http://inspec.io/) might be more useful for writing custom compliance controls.
It would be nice if there was a $CONGIG_MANAGEMENT_SYSTEM_OF_CHOICE module that did common security fixes, and you could just pick and choose which to apply.
On a side note: Holy ^&$% Lynis has a lot of shell! Like a crazy amount of POSIX shell code!