```
____
________ _____/ __/__ __________
/ ___/ _ \/ ___/ /_/ _ \/ ___/ ___/
(__ ) __/ /__/ __/ __(__ ) /__
/____/\___/\___/_/ \___/____/\___/
```
**Linux security inspection and audit tools.**



Two tools, one purpose
| Tool | Purpose | Run as |
|---|---|---|
| secfetch | Quick security overview | User |
| secscan | Deep security audit (Lynis-style) | User or root |
Install
pipx install secfesc
See the Installation guide for alternatives and startup integration.
Quick start
secfetch # Full security overview
secfetch --short # Compact fastfetch-style summary
secscan # Basic audit (no root)
secscan --quick # Essential checks only
secscan --category ssh # Audit a single category
sudo secscan --full # Complete audit (requires root)
secscan --report json --output report.json # Export findings
What secscan checks (v1.7.0)
| Category | Key checks |
|---|---|
| SSH | Root login, empty passwords, password auth, legacy protocol, X11 forwarding, MaxAuthTries |
| Users | Non-root UID 0 accounts, empty passwords (root), duplicate UIDs/names |
| Groups | Duplicate GIDs/names, extra root-group members |
| Authentication | Password ageing policy, weak hash method, UMASK (/etc/login.defs) |
| Firewall | Active firewall detection (firewalld / ufw / nftables / iptables) |
| Cron | World-writable cron paths/files, unrestricted cron policy |
| Permissions | Mode & ownership of /etc/passwd, /etc/group, /etc/shadow, /etc/gshadow |
More categories are on the roadmap.
Documentation
| Document | What it covers |
|---|---|
| Installation | Install, update, startup integration |
| Usage | Full CLI reference for both tools |
| Configuration | Enable/disable checks, choose your startup logo |
| Architecture | Project structure, how to add checks and logos |
| Roadmap | Where secscan is heading |
| Changelog | Release history |
Getting help
secfetch help # List all secfetch checks
secfetch help <check> # Details and fix hints for one check
secscan --help # secscan audit options
secfesc is licensed under the GNU General Public License v3.0.