
Security auditing tool for Linux and UNIX
Mature enough to put in production this quarter.
Small teams with Linux servers
Manual security audits
GPL-3.0 license may limit commercial use
Run lynis audit on a test server
GPL-3.0. This is a copyleft or source-available licence with obligations attached. Read the LICENSE file before shipping it inside a commercial product.
This is a reading of the licence label, not legal advice.
The numbers
Maintainers describe it as: “Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.”
lynis, in short
- Should a small team use lynis?
- Adopt now. Mature enough to put in production this quarter. Small teams with Linux servers
- What does lynis actually do?
- Security auditing tool for Linux and UNIX
- What does lynis replace?
- Manual security audits
- What is the downside of lynis?
- GPL-3.0 license may limit commercial use
- Can lynis be used in a commercial product?
- Its licence is GPL-3.0, which carries obligations or restrictions for commercial use. Read the LICENSE file, and get a lawyer's read before you ship it inside a product you sell.