
puppet-os-hardening
This puppet module provides numerous security-related configurations, providing all-round base protection.

This puppet module provides numerous security-related configurations, providing all-round base protection.

Terraform module to manage AWS Security Groups. Currently, the ingress and egress rules support IPv4, IPv6, and Security Group ID inputs.

Systematic Linux kernel hardening project implementing KSPP-recommended settings, module blacklisting, and restricted environment configuration for…

Ansible role for workaround for CVE-2017-2636 (Red Hat) - https://access.redhat.com/security/cve/CVE-2017-2636

Puppet Module to help fix and migrate a Puppet deployment (CVE-2011-3872)

Bash script to assess Linux host exposure to CVE-2026-31431, check kernel module status, apply mitigation by blocking algif_aead, and update kernel…

This puppet module provides secure ssh-client and ssh-server configurations.

Puppet module to harden ImageMagick policy.xml against CVE-2016-3714 by restricting dangerous image processing directives.

Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in…

Ansible playbook automating CVE-2016-5195 (Dirty COW) mitigation on CentOS/Scientific Linux using SystemTap kernel module generation.

Remediation task for CVE-2018-15686, CVE-2018-16866, and CVE-2018-16888 affecting SystemD in EL7

Kubernetes DaemonSet to detect and remediate CVE-2026-31431 (GHSA-2274-3hgr-wxv6) — algif_aead LPE via modprobe blacklist

Module PowerShell de réponse à l'incident CVE-2025-59287 — WSUS Remote Code Execution (RCE)

Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具

An Ansible Playbook to mitigate the vulnerability CVE-2026-31431 on RHEL-based and Debian-based OSes.

Seccomp-based mitigation for CVE-2026-31431, a Linux kernel LPE. Blocks AF_ALG socket via PAM module and standalone wrapper, with auto-detection of…

Quick mitigation and patch script for CVE-2026-31431 (Copy Fail) on Ubuntu/Debian VPS