Lynis
Audit Unix/Linux systems for security hardening gaps. Generates hardening recommendations.
Open the official app on cisofy.com
This tool is hosted by its maintainers. Click below to open cisofy.com in a new tab — it's their official demo.
Browse security tools →What's next with Lynis?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Lynis?
Lynis is an open-source security auditing tool designed for Linux, macOS, and Unix-based systems. Its primary purpose is to perform comprehensive health scans to identify vulnerabilities, enforce compliance with security standards, and strengthen system configurations. Developed since 2007 under the GPL-3.0 license, Lynis is widely used by system administrators, IT auditors, developers, and penetration testers. It addresses critical security gaps by detecting misconfigurations, outdated software, and potential attack vectors, making it essential for organizations aiming to meet regulatory requirements like PCI DSS, HIPAA, or ISO 27001. By automating audits and providing actionable insights, Lynis reduces manual workload while ensuring systems adhere to best practices for hardening and compliance.
How it works
Lynis is a battle-tested security tool that scans UNIX-based systems to assess their security posture. It supports Linux, macOS, AIX, FreeBSD, and other variants, offering a centralized way to evaluate risks and improve defenses. The tool combines automated checks with real-time feedback, helping users identify weak passwords, unnecessary services, and insecure file permissions. Its focus on compliance testing ensures systems align with industry standards, reducing the risk of breaches or regulatory penalties. Lynis performs vulnerability detection by analyzing system components, kernel modules, and third-party software. It checks for missing security patches, outdated libraries, and insecure configurations, such as improperly set SUID/SGID bits. For compliance testing, it verifies adherence to frameworks like PCI DSS and HIPAA by flagging non-compliant settings.
How to use it
- 1Install Lynis via package managers (e.g., `sudo apt install lynis` on Debian) or download the source code. 2. Run the scan using `sudo lynis audit system` to initiate a full security assessment. 3. Review the generated report, which includes risk ratings and remediation suggestions. 4. Apply fixes based on the findings and re-scan to verify improvements. Practical tips: Use `--help` to explore advanced options like customizing scan targets or focusing on specific compliance frameworks. Store logs securely and share findings with stakeholders to drive organizational change.
What it can do
- system security auditing
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/CISOfy/lynis
- license: GPL-3.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- For authorized use only — use on systems you own or have explicit permission to test.
- Does not support Windows-based systems or non-UNIX environments
- Lacks real-time monitoring capabilities for ongoing threat detection
- Limited graphical interface; requires command-line proficiency
- Does not automatically apply fixes, requiring manual intervention
Understanding the result
Audit Unix/Linux systems for security hardening gaps. Generates hardening recommendations.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (GPL-3.0).
- Built with
- (CISOfy/lynis)
- License
- GPL-3.0
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with CISOfy/lynis. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- GPL-3.0
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- GPL-3.0 License
Upstream project
Frequently asked
What operating systems does Lynis support?
Lynis runs on all UNIX-based systems including Linux, macOS, AIX, FreeBSD, HP-UX, NetBSD, OpenBSD, and Solaris. It does not support Windows or non-UNIX environments due to its reliance on Unix-specific tools and system calls.
How does Lynis perform compliance testing?
Lynis uses predefined rulesets aligned with standards like PCI DSS, HIPAA, and ISO 27001. During a scan, it checks system configurations against these frameworks, flagging deviations such as weak access controls or missing encryption protocols. Users can customize rulesets to match organizational policies.
How do I run a basic security audit with Lynis?
Install Lynis using your package manager (e.g., `sudo apt install lynis`), then execute `sudo lynis audit system` to initiate a scan. The tool will analyze system files, services, and configurations, outputting results to the terminal and a log file. Review the report for high-risk issues like open ports or outdated packages.
How does Lynis compare to tools like OpenVAS or Nessus?
Lynis focuses on system hardening and compliance testing, while OpenVAS and Nessus emphasize network vulnerability scanning. Lynis integrates with local system data for deeper configuration checks, whereas OpenVAS requires a separate agent for host discovery. Nessus offers more advanced exploit detection but lacks Lynis' built-in compliance frameworks.
How do I resolve permission errors when running Lynis?
Permission errors typically occur due to insufficient privileges. Run Lynis with `sudo` to access system files. If issues persist, check for missing dependencies using `sudo apt install -f` (Debian-based systems) or reinstall Lynis. Ensure the user has read access to critical directories like `/etc` and `/var/log`.