Linux Server Security Audit Checklist
The box itself - access, network, patches and permissions.
A server security audit reads the machine itself: who can reach it, what it is running, which files are writable by the wrong people, and how far behind it is on patches.
- Read-only, safe on production
- No agent installed
- ~76s for the category
- 10 distros auto-detected
How much of this is serious?
Severity of all 45 VPS & Server checks, as the scripts rate them.
- 13High severity29%
- 21Medium severity47%
- 11Low severity24%
What these audits cover
- Root login, key-based authentication, sudo grants and who can open a session
- Firewall state, listening ports, and services exposed beyond localhost
- World-writable paths, set-id binaries and sensitive file permissions
- Pending security updates, kernel state and whether a reboot is outstanding
What they do not cover
- Application-level bugs in the code you deploy. These audits read server configuration, not your source.
- Intrusion detection and brute-force blocking. Fail2Ban, sshguard and CrowdSec are not evaluated.
- Anything behind a managed platform you do not control. On Kubernetes or a PaaS there is no sshd to read.
The 7 VPS & Server audits
Roughly in the order that matters. SSH and access is the front door; firewall and network decides how much of the rest is even reachable.
SSH & Access
Root login, password auth, port, idle timeout, authorized keys and sudo privileges
Services & Processes
SoonAttack surface from services, listeners and scheduled jobs
File System
SoonDangerous permissions, set-id binaries and sensitive files
Firewall & Network
SoonFirewall state, exposed ports, Docker bypass and network policy
Application Security
SoonTLS certificates, runtime versions and database access
System Updates
SoonPending patches, automatic updates, kernel and reboot state
Logging & Monitoring
SoonSeparated logging and monitoring checks
Other categories
VPS & Server security questions
Run all 45 VPS & Server checks, in one click
CtrlOps runs these audits over your existing SSH connection - no agents, no scripts to manage. $7/user/month after a 1 month free trial - no credit card required.
✓ Start instantly·✓ No credit card·✓ No sneaky autorenewals