Lynis Security Auditing Software For Unix-Linux

LYNIS Security Auditing
LYNIS Security Auditing

Lynis 3.0.0 Released with new changes.

Lynis is a free and open source security and auditing software. It runs on Linux, macOS, and other Unix-based systems to performs an in-depth security scan.

The primary focus of Lynis is to perform a health check of systems. It helps also to detect security vulnerabilities and configuration management weaknesses, and discover configuration issues, including vulnerable packages, missing best practices, and weak defaults. With actionable plans and reports, it helps you to get back on track for your compliance needs, IT audits, or better security defenses.

Lynis performs an in-depth local scan on the system and is therefore much more thorough than network based vulnerability scanners.


Shell and basic utilities


Normal user or preferable root permissions

Linus Features

Supported platforms

Lynis supports Operating systems

  • AIX
  • FreeBSD
  • HP-UX
  • Linux
  • macOS
  • NetBSD
  • OpenBSD
  • Solaris
  • and others

Lynis Features

  • In-depth audits by host based scanning
  • Installation is optional
  • Even dependencies are optional
  • All Unix, Linux, BSD and macOS versions
  • Action plans, with priority based hardening strategies
  • Find undiscovered vulnerabilities
  • Compliance testing (PCI, HIPAA, SOx and others)
  • Intrusion detection and monitoring to detect intruders and monitor for configuration issues
  • Continuous auditing, discover changes
  • Layered dashboards (technical and managerial)
  • Reporting and data export
  • User management Different levels of user access
  • Open source software

What’s new in Lynis 3.0.0

  • This is a major release of Lynis and includes several big changes.

Security issues

This release resolves two security issues

  • CVE-2020-13882
  • CVE-2019-13033

Breaking change: Non-interactive by default

Lynis now runs non-interactive by default, to be more in line with the Unix philosophy. So the previously used ‘–quick’ option is now default, and the Lynis will only wait when using the ‘–wait’ option.

Breaking change: Deprecated options

– Option: -c
– Option: –check-update/–info
– Option: –dump-options
– Option: –license-key

Breaking change: Profile options

The format of all profile options are converted (from key:value to key=value).
You may have to update the changes you made in your custom.prf.


An important focus area for this release is on security, and added several measures to further tighten any possible misuse.


  • DevOps, Cyber Forensics, and pentesting mode
  • This release adds initial support to allow defining a specialized type of audit.
  • Using the relevant options, the scan will change base on the intended goal.

Download Lynis

For the latest update about Cyber and Infosec World, follow us on Twitter, Facebook, Telegram , Instagram and subscribe to our YouTube Channel.

Subscribe to HackersOnlineClub via Email

Enter your Email address to receive notifications of Latest Posts by Email | Join over Million Followers

Leave a Reply
Related Posts