Security Baseline and Hardening
Back to Home Lab Documentation Hub
Baseline Controls
- Host patch management and vulnerability remediation cadence.
- Service minimization to reduce exposed attack surface.
- Firewall policy based on deny-by-default and explicit allow rules.
- Administrative account separation for privileged tasks.
Threat Detection Stack
- Suricata/Snort for network intrusion signals.
- Wazuh for endpoint security telemetry and integrity monitoring.
- Graylog for central log search, triage, and retention workflows.
Hardening Validation
- Unauthorized ports and services are closed or monitored.
- Critical logs are centralized and timestamp-consistent.
- Alerting triggers for high-risk events are tested quarterly.