01
Clean install
LUKS / FDE
02
Core harden
UFW · updates
03
Modules
SSH · AppArmor
04
OpSec ops
Sandbox · audit
1. Factory Reset / Clean Install
- Perform a fresh install of your distribution (Ubuntu, Debian, Fedora, or Arch recommended).
- Enable full disk encryption (LUKS) during installation.
- Use a strong, unique passphrase.
2. Core Hardening
sudo apt update && sudo apt upgrade -yInstall and configure UFW:
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw enable3. Recommended Hardening Modules
- SSH hardening
- Kernel parameter tuning (sysctl)
- Auditd + logging improvements
- AppArmor enforcement
- Automatic security updates
4. Additional OpSec Recommendations
- Use Firejail or Bubblewrap for application sandboxing
- Run high-risk tools in a dedicated hardened VM
- Regularly audit with Lynis