How to Perform Security Auditing with Lynis on Linux Servers

Lynis is an open-source security scanner that evaluates Linux hardening by checking configurations, packages, and kernel parameters, producing actionable warnings and suggestions for remediation.

The imthenachoman/How-To-Secure-A-Linux-Server repository recommends Lynis as a foundational tool for assessing server security posture. This guide covers the complete workflow for implementing security auditing with Lynis on Debian-based systems, from installation via the official CISOFY repository to interpreting audit results.

What Is Lynis and Why Use It?

Lynis performs an extensive health scan of Linux, macOS, and Unix hosts. According to the repository's documentation in README.md#lynis---linux-security-auditing, the tool examines configuration files, installed packages, kernel parameters, and system settings to uncover potential security weaknesses.

Unlike basic vulnerability scanners, Lynis focuses on hardening compliance—identifying missing security controls, misconfigurations, and deviations from best-practice baselines. The output categorizes findings into actionable groups: warnings (critical issues), suggestions (improvements), and informational notes (reference data).

Installing Lynis from the Official CISOFY Repository

The guide emphasizes installing Lynis from the official CISOFY packages rather than distribution defaults. This ensures access to the latest vulnerability signatures and test profiles directly from the maintainers.

Add the repository and install the package:


# Install prerequisites

sudo apt install ca-certificates

# Create keyring directory

sudo mkdir -p /etc/apt/keyrings

# Download and install CISOFY signing key

wget -O - https://packages.cisofy.com/keys/cisofy-software-public.key \
  | sudo gpg --dearmor -o /etc/apt/keyrings/cisofy-lynis.gpg

# Add the Lynis repository

echo "deb [signed-by=/etc/apt/keyrings/cisofy-lynis.gpg] \
https://packages.cisofy.com/community/lynis/deb/ stable main" \
  | sudo tee /etc/apt/sources.list.d/cisofy-lynis.list

# Update package lists and install

sudo apt update
sudo apt install lynis

This installation places the lynis executable at /usr/bin/lynis and creates the default profile at /etc/lynis/default.prf, which defines the test scope for subsequent audits.

Running a System Security Audit

Before executing scans, refresh Lynis's internal vulnerability database to ensure accurate detection of recent security issues.

Update the vulnerability data:

sudo lynis update info

Execute a full system audit:

sudo lynis audit system

The command runs non-interactively, checking hundreds of hardening controls including file permissions, authentication settings, network configuration, and kernel security parameters. Output streams to the terminal while detailed logs write to /var/log/lynis.log for later review.

Interpreting Audit Results

Lynis categorizes findings into three distinct severity levels:

  • Warnings: Critical security gaps requiring immediate attention, such as missing kernel hardening parameters or world-writable directories
  • Suggestions: Recommendations for improving security posture, like enabling specific sysctl options or removing unnecessary services
  • Information: Contextual data about the system configuration that aids compliance reporting

Prioritize remediation by addressing all warnings first, then implement high-value suggestions to harden the attack surface. The tool references specific test IDs (e.g., SSH-7408 for SSH configuration) that map to detailed documentation on the CISOFY website.

Automating Security Audits

Regular re-evaluation ensures continuous compliance as system configurations drift over time. While the repository does not provide a ready-made systemd timer, Lynis integrates seamlessly with standard scheduling tools.

Create a nightly audit via cron:


# Edit crontab for root

sudo crontab -e

# Add this line to run at 02:30 daily

30 2 * * * /usr/bin/lynis audit system > /var/log/lynis-audit.log 2>&1

For enterprise environments, customize the audit scope by modifying /etc/lynis/default.prf to skip tests irrelevant to your infrastructure or to enforce stricter compliance baselines.

Summary

  • Lynis provides comprehensive security auditing with Lynis by scanning configurations, packages, and kernel parameters against hardening baselines.
  • Install from the CISOFY repository rather than distribution packages to maintain updated vulnerability signatures.
  • Run lynis audit system after executing lynis update info to ensure current detection capabilities.
  • Address warnings before suggestions when remediating findings to maximize security impact.
  • Store logs in /var/log/lynis.log and schedule regular audits via cron for continuous compliance monitoring.

Frequently Asked Questions

Do I need to run Lynis as root?

Yes. Lynis requires root privileges to access system configuration files, read kernel parameters, and inspect file permissions across the entire filesystem. Execute all audit commands with sudo or as the root user to ensure complete coverage.

How often should I run security audits?

Run initial audits after any system configuration change, then schedule recurring audits weekly or monthly depending on your environment's volatility. For high-security production servers, daily automated scans via cron provide the earliest detection of configuration drift or new vulnerabilities.

Can I use Lynis on non-Debian distributions?

Yes. While this guide focuses on Debian/Ubuntu installation via the CISOFY repository, Lynis supports RHEL, CentOS, Fedora, Arch Linux, macOS, and other Unix variants. Download the latest tarball from CISOFY or install via your distribution's package manager, though the official repository guarantees the most current test definitions.

What is the difference between warnings and suggestions in Lynis output?

Warnings indicate active security risks or compliance violations that demand immediate remediation, such as missing patches or insecure service configurations. Suggestions represent optimization opportunities that improve hardening but don't necessarily indicate current vulnerabilities—address these after resolving all warnings to achieve defense-in-depth.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →