← All cheat sheets

LYNIS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Lynis is an open-source security auditing tool for Unix/Linux
systems. It performs in-depth system hardening checks, compliance
testing, and vulnerability detection. Used by system admins,
auditors, and pentesters.

BASIC USAGE#

lynis audit system               # Full system audit
lynis audit system --quick       # Quick scan
lynis show profiles              # Show available profiles

AUDIT COMMANDS#

lynis audit system               # Complete system audit
lynis audit system --quick       # Quick audit (skip user input)
lynis audit system --pentest     # Penetration test mode
lynis audit system --forensics   # Forensics mode
lynis audit dockerfile <file>    # Audit Dockerfile

SCAN OPTIONS#

lynis audit system --no-colors   # Disable colored output
lynis audit system --reverse-colors
                                 # Reverse colors (light terminal)
lynis audit system --quiet       # Quiet mode
lynis audit system --verbose     # Verbose output
lynis audit system --debug       # Debug mode
lynis audit system --cronjob     # Non-interactive (for cron)

PROFILE OPTIONS#

lynis audit system --profile <file>
                                 # Use custom profile
lynis show profiles              # List available profiles
lynis show settings              # Show active settings
lynis show categories            # List test categories

TEST SELECTION#

lynis audit system --tests-from-group <group>
                                 # Run specific test group only
lynis audit system --tests <TEST-ID>
                                 # Run specific test(s)
lynis audit system --skip-test <TEST-ID>
                                 # Skip specific test

TEST CATEGORIES#

# boot_services        - Boot and services
# kernel               - Kernel hardening
# memory_processes     - Memory and processes
# software             - Software: packages and updates
# networking           - Networking
# printers_spools      - Printers and spools
# email                - Email and messaging
# firewalls            - Firewalls
# webservers           - Web servers
# ssh                  - SSH server
# snmp                 - SNMP
# databases            - Databases
# ldap                 - LDAP services
# php                  - PHP
# squid                - Squid proxy
# logging              - Logging and files
# insecure_services    - Insecure services
# banners              - Banners and identification
# scheduled_tasks      - Scheduled tasks
# accounting           - Accounting
# time                 - Time and NTP
# crypto               - Cryptography
# virtualization       - Virtualization
# containers           - Containers
# security_frameworks  - Security frameworks
# file_integrity       - File integrity
# malware              - Malware
# file_permissions     - File permissions
# home_directories     - Home directories
# kernel_hardening     - Kernel hardening
# storage              - Storage
# authentication       - Authentication
# shells               - Shells
# usb                  - USB devices

INFORMATION COMMANDS#

lynis show version               # Show version
lynis show commands              # Show available commands
lynis show help                  # Show help
lynis show tests                 # List all tests
lynis show tests-group <group>   # Tests in specific group
lynis show details <TEST-ID>     # Show test details
lynis show hostids               # Show host IDs
lynis show plugins               # List plugins

OUTPUT & REPORTING#

lynis audit system --report-file <file>
                                 # Custom report file location
lynis audit system --log-file <file>
                                 # Custom log file location

# Default output files:
# /var/log/lynis.log             - Detailed log
# /var/log/lynis-report.dat      - Machine-readable report

# Parse report data:
grep "suggestion" /var/log/lynis-report.dat
grep "warning" /var/log/lynis-report.dat
grep "hardening_index" /var/log/lynis-report.dat

HARDENING INDEX#

# Score 0-100 (higher = better)
# 80+   = Well hardened
# 60-79 = Decent security
# 40-59 = Needs improvement
# <40   = Significant issues

REMOTE SCANNING#

# Scan remote system via SSH:
ssh user@remote "lynis audit system --cronjob --quiet" > remote_report.txt

# Or use Lynis Enterprise for centralized scanning

EXAMPLES#

# Full system audit
sudo lynis audit system

# Quick automated scan (for scripts/cron)
sudo lynis audit system --cronjob --quiet

# Pentest mode (non-privileged)
lynis audit system --pentest

# Test only SSH configuration
sudo lynis audit system --tests-from-group ssh

# Test only firewall configuration
sudo lynis audit system --tests-from-group firewalls

# Skip specific tests
sudo lynis audit system --skip-test SSH-7408 --skip-test SSH-7412

# Generate compliance report
sudo lynis audit system --profile /etc/lynis/cis.prf

COMPLIANCE PROFILES#

# CIS Benchmark checking
# HIPAA compliance
# PCI DSS requirements
# SOC2 controls
# ISO 27001 controls (Enterprise)
# Custom profiles supported

NOTES#

- Run as root for complete results
- Non-privileged mode available (pentest mode)
- No agents required
- Supports Linux, macOS, FreeBSD, OpenBSD, Solaris
- Enterprise version adds dashboard and compliance
- Reports saved to /var/log/lynis-report.dat
- Great for baseline security assessment
- Update regularly: lynis update info