VPS Linux security audit with Lynis and Auditd

Running a security audit on your VPS Linux is essential after deploying a new server, and should be repeated periodically. This guide uses Lynis, the most popular open-source security auditing tool for Linux systems.

What is Lynis?

Lynis is an open-source security auditing tool for Unix/Linux that performs 300+ security checks covering OS hardening, file permissions, network configuration, authentication, logging, and more. It provides a Hardening Index score (0-100) with actionable suggestions.

Install Lynis

Method 1: Package Manager (Ubuntu/Debian)

sudo apt-get install lynis -y

Method 2: Download from GitHub (newer version)

cd /tmp
curl -o lynis.tar.gz https://downloads.cisofy.com/lynis/lynis-3.1.3.tar.gz
tar xfz lynis.tar.gz
mv lynis /usr/local/lynis

Run a Security Audit

sudo lynis audit system

Lynis scans the entire system in 2-5 minutes. Results are shown in three categories:

The report ends with a Hardening Index such as Hardening index: 65 — aim for 70+.

View Detailed Lynis Results

sudo cat /var/log/lynis.log | grep "Warning\|Suggestion" | head -30

Understanding the Hardening Index and Score Ranges

The Hardening Index reflects your server's overall security posture. A higher score doesn't guarantee zero vulnerabilities, but indicates you've followed common hardening practices. Here's how to interpret the ranges:

Index Range Level Meaning Action
0–49 Weak Fresh server or multiple critical issues found Urgent fixes needed before going to production
50–69 Fair Some hardening done, multiple warnings remain Address warnings one by one
70–84 Good Follows most best practices, suitable for production Maintain and run audits regularly
85–100 Excellent Comprehensively hardened, ideal for high-security servers Audit every 3 months to maintain posture

Remember that a high Hardening Index does not guarantee complete security. Application-level vulnerabilities and zero-day exploits are outside Lynis's scope, so pair it with other security tools.

Common Fixes

1. SSH Hardening

# Edit /etc/ssh/sshd_config
PermitRootLogin no
PasswordAuthentication no
Protocol 2
MaxAuthTries 3

2. Disable Unused Services

sudo systemctl disable avahi-daemon
sudo systemctl disable cups

3. sysctl Hardening

# Add to /etc/sysctl.conf
net.ipv4.conf.all.rp_filter = 1
net.ipv4.tcp_syncookies = 1
kernel.dmesg_restrict = 1

Advanced Auditd Rules for Detailed Monitoring

Beyond basic Auditd installation, adding audit rules lets you capture specific high-value events such as modifications to critical configuration files, sudo usage, user account changes, and access to sensitive directories. This gives you an immutable audit trail for forensic investigation.

# List existing audit rules
sudo auditctl -l

# Watch /etc/passwd and /etc/shadow for write/attribute changes
sudo auditctl -w /etc/passwd -p wa -k passwd_changes
sudo auditctl -w /etc/shadow -p wa -k shadow_changes

# Track sudo command executions
sudo auditctl -a always,exit -F arch=b64 -S execve -F euid=0 -k sudo_commands

# Save rules permanently
sudo nano /etc/audit/rules.d/hardening.rules

Recommended hardening.rules content:

# Monitor sensitive configuration files
-w /etc/passwd -p wa -k passwd_changes
-w /etc/shadow -p wa -k shadow_changes
-w /etc/sudoers -p wa -k sudoers_changes
-w /etc/ssh/sshd_config -p wa -k sshd_config
-w /var/log/auth.log -p wa -k auth_log

# Track privileged command execution
-a always,exit -F arch=b64 -S execve -F euid=0 -k privileged_exec

Reload Auditd after adding rules:

sudo systemctl restart auditd
# Verify rules are loaded
sudo auditctl -l

Search audit events by key:

# Find passwd change events
sudo ausearch -k passwd_changes -i

# View daily audit summary report
sudo aureport --summary

Additional Security Hardening Tools to Use with Lynis

Lynis identifies problems but doesn't fix them automatically. These complementary tools help you build a layered security posture on your VPS:

Install and run rkhunter for rootkit detection:

sudo apt-get install rkhunter -y
sudo rkhunter --update
sudo rkhunter --check --sk

Note: many rkhunter WARNINGs are false positives from normal system customisation. Always review context before acting on results.

Tool Type Purpose Free
Lynis Security Auditor Full system hardening assessment Yes
Auditd System Logging Real-time system call and file access logging Yes
Fail2Ban Intrusion Prevention Automatic IP banning for brute force Yes
rkhunter Rootkit Scanner Detect rootkits and backdoors Yes
AIDE File Integrity Detect unauthorised file system changes Yes

Automating Security Monitoring and Alerts

Manual audits alone are insufficient for production servers. Set up automated alerting so you know when something changes. The simplest approach is a weekly cron job that runs Lynis and logs results via syslog, combined with Auditd forwarding to a centralised log system.

Schedule a weekly Lynis scan:

# Open crontab
sudo crontab -e

# Run Lynis every Sunday at 02:00 and log output
0 2 * * 0 /usr/bin/lynis audit system --quiet 2>&1 | /usr/bin/logger -t lynis-weekly

Review the weekly log via journal:

sudo journalctl -t lynis-weekly --since "7 days ago"

For Auditd, configure log rotation to preserve history in /etc/audit/auditd.conf:

# /etc/audit/auditd.conf
log_format = ENRICHED
num_logs = 10
max_log_file = 100
max_log_file_action = ROTATE

Beyond logging, define a clear incident response plan: when Lynis finds a new Warning or Auditd logs a suspicious event, know exactly who to notify, how to isolate the server if needed, and where backups are stored. Regular drills ensure your team can act quickly when a real incident occurs.

Install Auditd for System Call Logging

sudo apt-get install auditd -y
sudo systemctl enable auditd && sudo systemctl start auditd

View audit logs:

sudo ausearch -ts recent -i | head -50

Recommendation: Run Lynis every 1-3 months or after installing new software. Aim for a Hardening Index above 70 and address all Warnings before they accumulate.

VPS Linux Ready to Deploy and Secure

AsiaGB VPS in Thailand and Singapore — Full Root Access to configure security your way. Plans from 500 THB/month.

View VPS Plans