Automated CIS, STIG, and PCI-DSS hardening across Ubuntu, Debian, RHEL, Rocky, and Amazon Linux. Dry-run everything. Roll back anything. Report in JSON, HTML, or Markdown.
hardbox removes the guesswork from Linux hardening. Audit, plan, apply, and roll back — all from a single binary with zero dependencies.
--non-interactive flag. Drop it into Ansible, Terraform, cloud-init, or GitHub Actions.Every module implements the same interface — Audit, Plan, Apply, Rollback — and ships with table-driven unit tests and compliance references.
A single statically-linked binary. No runtime dependencies. No CGO. Runs on any Linux x86_64 or ARM64 server.
Profiles define which modules run, which checks are enforced, and what severity thresholds trigger CI failures.
| Profile | Framework | Best For | Status |
|---|---|---|---|
| cis-level1 | CIS Benchmarks L1 | Minimum baseline | ● Shipped |
| production | hardbox curated | Cloud production | ● Shipped |
| development | hardbox curated | Dev/staging | ● Shipped |
| Profile | Framework | Target |
|---|---|---|
| cis-level2 | CIS Benchmarks L2 | v0.2 |
| stig | DoD STIG | v0.2 |
| pci-dss | PCI-DSS v4.0 | v0.2 |
| hipaa | HIPAA Security Rule | v0.3 |
| nist-800-53 | NIST SP 800-53 Rev.5 | v0.3 |
| iso27001 | ISO/IEC 27001:2022 | v0.3 |
hardbox is open source, MIT licensed, and built for production. Start hardening today.