Audit every authorized_keys file on a Linux server
Audit every authorized_keys file on a Linux server. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery…
Bastion host security: smaller, stricter, and observable
Bastion host security: smaller, stricter, and observable. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…
The Docker socket is root access wearing an API
The Docker socket is root access wearing an API. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery path.
Fail2ban for SSH: useful guardrail, not your primary lock
Fail2ban for SSH: useful guardrail, not your primary lock. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…
Credential rotation after a server incident: the order matters
Credential rotation after a server incident: the order matters. Audit the exposure, understand the threat model, apply changes safely, and keep an…
Linux patching without surprise reboots or broken services
Linux patching without surprise reboots or broken services. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…
Suspect a Linux rootkit? Preserve evidence before installing scanners
Suspect a Linux rootkit? Preserve evidence before installing scanners. Audit the exposure, understand the threat model, apply changes safely, and keep an…
Nftables basics for an SSH host
Nftables basics for an SSH host. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery path.
Stop leaving secrets in shell history and deployment folders
Stop leaving secrets in shell history and deployment folders. Audit the exposure, understand the threat model, apply changes safely, and keep an…
SSH agent forwarding can turn a server into your identity
SSH agent forwarding can turn a server into your identity. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…
SSH certificates: when authorized_keys stops scaling
SSH certificates: when authorized_keys stops scaling. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…
SSH hardening checklist for a public Linux server
SSH hardening checklist for a public Linux server. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery path.
REMOTE HOST IDENTIFICATION HAS CHANGED: attack or rebuild?
REMOTE HOST IDENTIFICATION HAS CHANGED: attack or rebuild?. Audit the exposure, understand the threat model, apply changes safely, and keep an independent…
Audit NOPASSWD sudo before it becomes instant root
Audit NOPASSWD sudo before it becomes instant root. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery…
UFW for SSH servers without locking yourself out
UFW for SSH servers without locking yourself out. Audit the exposure, understand the threat model, apply changes safely, and keep an independent recovery path.
Who can SSH into your server right now? You probably don't know.
Audit SSH access across every user, remove stale keys and unsafe NOPASSWD sudo rules, then harden sshd without locking yourself out.