• Stars
    star
    609
  • Rank 73,614 (Top 2 %)
  • Language
  • Created over 8 years ago
  • Updated about 3 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Repository of Hardening Guides

ERNW Repository of Hardening Guides

This repository contains various hardening guides compiled by ERNW for various purposes. Most of those guides strive to provide a baseline level of hardening and may lack certain hardening options which could increase the security posture even more (but may have impact on operations or required operational effort).

The hardening guides are structured into various categories, represented by folders. Every hardening guide must be used in combination with hardening guides of the parent folders. Let's use the following fictional structure as an example:

  • web_application
  • ERNW_Hardening_Web_Application.md
  • wordpress
    • ERNW_Hardening_Wordpress.md
    • 4.4.2
    • ERNW_Hardening_Wordpress_4.4.2.md

In this structure, all three files 'ERNW_Hardening_Web_Application.md', 'ERNW_Hardening_Wordpress.md', and 'ERNW_Hardening_Wordpress_4.4.2.md' need to be taken into account for comprehensive hardening. If there are conflicting options, the most specific option (in this case, from 'ERNW_Hardening_Wordpress_4.4.2.md') must be used.

Contact us!

Feel free to contact us for questions, additions, spotted mistakes, or -- you name it.

Other Hardening Sources

The following incomplete list contains several other high quality hardening resources:

More Repositories

1

nmap-parse-output

Converts/manipulates/extracts data from a Nmap scan output.
XSLT
511
star
2

ss7MAPer

SS7 MAP (pen-)testing toolkit. DISCONTINUED REPO, please use: https://github.com/0xc0decafe/ss7MAPer/
Erlang
450
star
3

static-toolbox

A collection of statically compiled tools like Nmap and Socat.
Shell
417
star
4

AndroTickler

Penetration testing and auditing toolkit for Android apps.
Java
234
star
5

Windows-Insight

The content of this repository aims to assist efforts on analysing inner working principles, functionalities, and properties of the Microsoft Windows operating system. This repository stores relevant documentation as well as executable files needed for conducting analysis studies.
JavaScript
150
star
6

dizzy

Network and USB protocol fuzzing toolkit.
Python
66
star
7

insinuator-snippets

A collection of code snippets used in blog posts.
Python
54
star
8

net.tcp-proxy

A python based library to interact with .net webservices with net.tcp binding. Supports MC-NMF, MC-NMFTB and MS-NNS and contains a proxy for reading communications with webservices which require the negotiate encryption.
Python
54
star
9

quarantine-formats

Documentation and parsers for different anti-virus quarantine formats.
40
star
10

python-wcfbin

A python library for converting between WCF binary xml and plain xml.
Python
40
star
11

dizzy-legacy

Network and USB protocol fuzzing toolkit.
Python
34
star
12

binja-ipython

A plugin to integrate an IPython kernel into Binary Ninja.
Python
29
star
13

burpsuite-extensions

A collection of Burp Suite extensions
Java
29
star
14

ctf-writeups

Collection of CTF writeups
Python
15
star
15

dizzfiles

Fuzzing scripts used with the dizzy fuzzing toolkit.
Python
7
star
16

cvss-calculator

A wxpython based cvss calculator/viewer
Python
7
star
17

diameter_enum

A diameter Application and service scanner.
Python
6
star
18

forensic-hsts-analyzer

Tool to analyze HSTS caches during file system analysis.
6
star
19

open_mail_relay_tester

Python script to test for open mail relays (able to use HTTP proxies)
Python
6
star
20

tr19-badge-apps

The Troopers 19 badge apps.
Python
5
star
21

bcfs-fuse

C
4
star
22

tr19-badge-firmware

The Troopers 19 badge firmware based on MicroPython.
C
4
star
23

steampipe-plugin-openstack

Use SQL to query cloud resources and their configuration from OpenStack.
Go
4
star
24

gpfs-research

IBM GPFS related code
C
1
star
25

bcfs-manager

Python
1
star
26

tr19-badge-backend

The Troopers 19 badge provisioning server used to distribute applications and settings to your badge.
Python
1
star