Linux Control Depth

Linux Security Lite

Linux Security Lite delivers deep Linux audit coverage as a lightweight companion to the Audit Admin Toolkit. It provides 500 audit scripts across 11 domains with a versioned control catalogue, stable ID lock, and CI guard enforcement.

v1.1.4

Capabilities

Key Features

🐧

Linux Security Lite

Linux control depth extension for the AuditToolkit

  • 500 Linux audit scripts across 11 domains: platform (140), apps (67), cloud (57), security (56), network (44), data (36), advanced-controls (24), automation (22), storage (23), web (25), Alpine (6)
  • Versioned control catalogue with stable ID lock and CI guard enforcement
  • Control plane contract v1 for result ingest and export operations
  • Idempotent outbound queue with dead-letter and replay support
  • SIEM webhook push and GitHub issue creation from audit findings
  • RHEL, Debian, Ubuntu, SLES, Alpine, Arch, and openSUSE support
  • CI/CD compliance gate integration

Data Flow

How Linux Security Lite executes

Linux Security Lite provides multiple access methods to reach Linux hosts, from direct local execution to agent-based or remote SSH collection, adapting to your deployment topology.

flowchart TB TOOL["Linux Security Lite"] LOCAL["Local Execution"] SSH["SSH"] AGENT["Fleet Agent"] LINUX["Linux Hosts"] TOOL --> LOCAL TOOL --> SSH TOOL --> AGENT LOCAL --> LINUX SSH --> LINUX AGENT --> LINUX

Ready to evaluate Linux Security Lite?

Contact us to arrange an evaluation or request access to the full documentation set.