CISOfy/lynis

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening....

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 42 minutes ago
Added to GitGenius on June 21st, 2026
Created on December 10th, 2013
Open Issues & Pull Requests: 218 (+0)
Number of forks: 1,620
Total Stargazers: 16,215 (+0)
Total Subscribers: 344 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 6.9 days
Mean response time: 82.3 days
90th percentile: 298.8 days
Tracked items: 119

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 100% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Work labelled "bug" is answered fastest, typically in about 18 hours, while "information-needed" waits about 7 days. Only 6% of issues opened in the past year have been closed. Three people close 80% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 92
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 512 days
Stale 30+ days: 89
Stale 90+ days: 84

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • no-change (16)
  • bug (14)
  • needs-confirmation (13)
  • information-needed (11)
  • enhancement (9)
  • waiting-for-pull-request (9)
  • external cause (5)
  • help-wanted (3)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Lynis is a security auditing tool written in Shell that performs in-depth security scans on UNIX-based systems including Linux, macOS, BSD, and other variants. The tool runs directly on the target system in an agentless manner and requires no installation, making it accessible for quick deployment. Users can execute Lynis by cloning the repository and running the audit command immediately, or install it through various package managers and distribution repositories.

The primary purpose of Lynis is to test security defenses and identify opportunities for system hardening. It scans for vulnerable software packages, configuration issues, and general system information while providing actionable recommendations for improving security posture. The tool serves multiple audiences including system administrators, security auditors, security officers, penetration testers, and security professionals. It has become a standard component in both defensive security operations and offensive penetration testing engagements.

Lynis directly supports compliance testing for major regulatory frameworks including HIPAA, ISO27001, and PCI DSS. Beyond compliance, the tool assists with configuration and asset management, software patch management, system hardening, privilege escalation testing, and intrusion detection. The software emphasizes simplicity, regular updates, and openness, allowing users to understand and modify the codebase according to their needs.

The most frequently applied issue labels are bug, no-change, and needs-confirmation, suggesting the project manages a steady stream of bug reports and triage activities.

Installation flexibility is a key design feature, with Lynis available through RPM and DEB packages maintained by the CISOfy project, distribution-specific repositories, direct tarball downloads, and Git clones. The tool has received significant industry recognition, including placement in ToolsWatch Best Tools rankings across multiple years and recognition in the 2016 Best of Open Source Software Awards.

The project participates in the Linux Foundation's CII best practices badge program, demonstrating commitment to security and quality standards. An enterprise version exists for organizations requiring additional functionality such as web interfaces, dashboards, reporting capabilities, hardening snippets, and commercial support, though the open-source version remains fully functional for security auditing and compliance testing purposes.