Skip to main content

Claude Prompt for a Linux Server Hardening Checklist Script

Generate a server hardening script that audits and remediates security configs following CIS benchmarks — SSH, firewall, auditd, and password policy.

Fill in the placeholders

Edit the values, then copy your finished prompt.

Your Prompt
prompt.txt
Write a Bash script that audits and hardens a Ubuntu 22.04 LTS server following CIS Level 1 benchmarks. The server runs Nginx, PostgreSQL, Redis and is accessed by 4 administrators. The script should: 1) Audit SSH configuration — disable root login, enforce key-only authentication, change the default port to 2222, set idle timeout, and limit max auth tries. 2) Configure the firewall using ufw allowing only ports 80, 443, 2222 and enabling rate limiting on SSH. 3) Disable unnecessary services and remove unused packages — enumerate running services and flag non-essential ones for review. 4) Set up automatic security updates with unattended-upgrades for critical patches only. 5) Configure auditd rules for monitoring file access to /etc/passwd, /etc/shadow, and /var/www, /opt/app/config. 6) Enforce password policies — minimum length 14, complexity requirements, account lockout after 5 failed attempts. 7) Set proper file permissions on sensitive directories and enable AIDE for file integrity monitoring. 8) Generate a final HTML report summarizing all findings with PASS/FAIL/MANUAL-REVIEW status for each check.

What this prompt does

This prompt writes a Bash script that audits and hardens a [distro] server against [security_framework] benchmarks, given the server runs [primary_services] and is used by [user_count] admins. It works through SSH hardening (root login off, key-only auth, port [ssh_port], idle timeout, max auth tries), firewall config with [firewall_tool] allowing only [allowed_ports], disabling unused services, unattended-upgrades, auditd rules for sensitive files plus [monitored_paths], password policy, file permissions with AIDE, and an HTML PASS/FAIL/MANUAL-REVIEW report.

The variables tailor the hardening to your environment. [distro] and [security_framework] set which benchmark and tooling apply, [ssh_port] and [allowed_ports] define the network surface, and [monitored_paths] extends auditd beyond the default sensitive files. The PASS/FAIL/MANUAL-REVIEW report framing ensures the script documents what it changed and what still needs a human. That report is as valuable as the remediation itself: it gives you an auditable record of the server's posture, and the MANUAL-REVIEW category acknowledges that some controls (which services are truly unnecessary, for instance) are judgment calls a script should flag rather than silently enforce.

When to use it

  • Bringing a fresh server into production and you want a hardening pass first
  • Auditing an existing box against [security_framework] like a CIS benchmark
  • You want a record of what was changed versus what needs manual review
  • Locking down SSH, then firewall, then auditd and file integrity in order
  • Enforcing password policy and account lockout consistently
  • Setting up AIDE for file integrity monitoring on sensitive directories

Example output

You get a Bash script organized by control area: SSH config edits, [firewall_tool] rules for [allowed_ports], a service enumeration and flagging step, unattended-upgrades setup, auditd rules, password policy changes, permission fixes plus AIDE, and a final HTML report marking each check PASS, FAIL, or MANUAL-REVIEW. The script audits and remediates, with the report summarizing both.

Pro tips

  • Confirm [ssh_port] and [allowed_ports] agree before running; changing the SSH port without opening it in [firewall_tool] is the classic way to lock yourself out
  • Keep a second logged-in session open while applying SSH changes so a bad config does not strand you
  • Treat MANUAL-REVIEW items as real work — automated remediation cannot safely decide everything, and the report flags those for a reason
  • Match [security_framework] to your compliance target; CIS Level 1 and Level 2 differ in how aggressive the controls are
  • Extend [monitored_paths] to your app's config and data directories so auditd catches tampering beyond /etc/passwd and /etc/shadow
  • Run the audit-only pass first if the script supports it, review the report, then apply remediation rather than hardening blind
  • Enable unattended-upgrades for critical patches only as the prompt specifies; auto-applying every update on a production box invites surprise breakage

Frequently Asked Questions

Will this lock me out of the server when it changes the SSH port?
It can if `[ssh_port]` and `[allowed_ports]` are inconsistent or you have no second session open. Always confirm the firewall allows the new port and keep a separate logged-in session while applying SSH changes, so a broken config does not strand you on a remote box.
Does the script just audit, or does it also fix issues?
It does both. The prompt asks it to audit configurations and remediate them, then generate an HTML report marking each check PASS, FAIL, or MANUAL-REVIEW. The MANUAL-REVIEW status flags decisions that are not safe to automate and need a human.
Can I follow a specific benchmark like CIS Level 1?
Yes. Set `[security_framework]` to the benchmark you target, such as CIS Level 1, and the controls follow it. Be aware that higher levels apply stricter, sometimes more disruptive settings, so choose the level that matches your operational and compliance needs.
What does the auditd part monitor by default?
It configures auditd rules to monitor access to sensitive files like /etc/passwd and /etc/shadow, plus any `[monitored_paths]` you add such as your web root or app config. This gives you an audit trail when those files are read or modified, which is useful for detecting tampering.
Engr Mejba Ahmed

Need this built for real?

Engr Mejba Ahmed

AI Developer · Software Engineer

I'm Mejba — I design and ship production AI systems, automations, and full-stack apps. If you want this turned into a working solution for your team, let's talk.

More in Linux & Shell Scripting Prompts

Engr Mejba Ahmed

Engr Mejba Ahmed

AI assistant · trained on my work

👋

Hey there!

Quick Actions

WhatsApp Direct line to me

Chat on WhatsApp

+880 1723 741224 · Replies within the hour on working days

Popular Questions

Engr Mejba Ahmed is connected
Engr Mejba Ahmed is typing...
Engr Mejba Ahmed avatar

✉ Want me to follow up? Drop your email

Engr Mejba Ahmed avatar

📞 Connect Directly

Choose how you'd like to reach me

WhatsApp

+880 1723 741224

Email

mejba.13@gmail.com

✓ Details sent! I'll get back to you shortly.

Powered by OpenAI

335+

Blog Posts

25

AI Courses

63

Projects

Services & Expertise

Pricing & Process

Learning & Resources

Connect & Support