Topic

Security

Security guides from Tryssh: practical diagnostics, safe operating procedures, and production runbooks for server operators.

Audit every authorized_keys file on a Linux server

Audit every authorized_keys file on a Linux server. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery…

The Tryssh team · July 21, 2026

Bastion host security: smaller, stricter, and observable

Bastion host security: smaller, stricter, and observable. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…

The Tryssh team · July 21, 2026

The Docker socket is root access wearing an API

The Docker socket is root access wearing an API. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery path.

The Tryssh team · July 21, 2026

Fail2ban for SSH: useful guardrail, not your primary lock

Fail2ban for SSH: useful guardrail, not your primary lock. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…

The Tryssh team · July 21, 2026

Credential rotation after a server incident: the order matters

Credential rotation after a server incident: the order matters. Audit the exposure, understand the threat model, apply changes safely, and keep an…

The Tryssh team · July 21, 2026

Linux patching without surprise reboots or broken services

Linux patching without surprise reboots or broken services. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…

The Tryssh team · July 21, 2026

Suspect a Linux rootkit? Preserve evidence before installing scanners

Suspect a Linux rootkit? Preserve evidence before installing scanners. Audit the exposure, understand the threat model, apply changes safely, and keep an…

The Tryssh team · July 21, 2026

Nftables basics for an SSH host

Nftables basics for an SSH host. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery path.

The Tryssh team · July 21, 2026

Stop leaving secrets in shell history and deployment folders

Stop leaving secrets in shell history and deployment folders. Audit the exposure, understand the threat model, apply changes safely, and keep an…

The Tryssh team · July 21, 2026

SSH agent forwarding can turn a server into your identity

SSH agent forwarding can turn a server into your identity. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…

The Tryssh team · July 21, 2026

SSH certificates: when authorized_keys stops scaling

SSH certificates: when authorized_keys stops scaling. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…

The Tryssh team · July 21, 2026

SSH hardening checklist for a public Linux server

SSH hardening checklist for a public Linux server. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery path.

The Tryssh team · July 21, 2026

REMOTE HOST IDENTIFICATION HAS CHANGED: attack or rebuild?

REMOTE HOST IDENTIFICATION HAS CHANGED: attack or rebuild?. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…

The Tryssh team · July 21, 2026

Audit NOPASSWD sudo before it becomes instant root

Audit NOPASSWD sudo before it becomes instant root. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery…

The Tryssh team · July 21, 2026

UFW for SSH servers without locking yourself out

UFW for SSH servers without locking yourself out. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery path.

The Tryssh team · July 21, 2026

Who can SSH into your server right now? You probably don't know.

Audit SSH access across every user, remove stale keys and unsafe NOPASSWD sudo rules, then harden sshd without locking yourself out.

The Tryssh team · July 19, 2026