Alternatives to Lynis
Audit Unix-like systems for hardening opportunities. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
Lynis
Audit Unix-like systems for hardening opportunities.
Replacements
Listings that take over the same core job as Lynis.
OpenSCAP
Open source tools for scanning systems against SCAP security policies and hardening baselines.
OpenSCAP scans against NIST SCAP policies and hardening baselines with a GUI option, but runs on Linux only and requires familiarity with SCAP profiles.
CIS-CAT Lite
A free tool from the Center for Internet Security that checks systems against CIS Benchmarks.
CIS-CAT Lite checks systems against official CIS Benchmarks on Windows, macOS and Linux, but is proprietary and requires a registration form to download.
Also worth comparing
These listings name Lynis as their own alternative, so the relationship runs both ways.
chkrootkit
A command-line tool that checks Unix-like systems locally for signs of a rootkit.
Lynis audits Unix-like systems for hardening opportunities and reports suggestions rather than focusing on known rootkit signatures like chkrootkit.
Similar software
Related functionality, not a direct replacement.
Vuls
Assess known vulnerabilities on Linux and FreeBSD systems.
kube-bench
Check Kubernetes settings against CIS benchmark tests.
ssh-audit
Review SSH client and server configurations.
Microsoft Security Compliance Toolkit
Microsoft tools and security baselines for analyzing, testing and comparing Windows security configurations.
Wazuh Agent
Endpoint agent that feeds a Wazuh server with security and compliance data.
Kicksecure
Hardened Debian derivative with kernel hardening and exploit mitigations.