# Security Automation Bundle (Devuan)

This directory contains production-ready security automation assets for a Devuan server, designed for SysV init environments that use cron for scheduling.

## Purpose

The goal of this bundle is to provide a practical baseline security workflow with repeatable checks, reliable logging, and cron-compatible wrappers.

## What This Directory Contains

- `bin/security_aide_check.sh`: Weekly file integrity verification using AIDE.
- `bin/security_malware_scan.sh`: Weekly malware/rootkit scan runner for rkhunter and chkrootkit (when installed).
- `bin/security_lynis_audit.sh`: Monthly Lynis hardening audit with report archival and summary output.
- `cron.weekly/aide-check`: Wrapper for weekly AIDE execution from the default deployment path.
- `cron.weekly/malware-scan`: Wrapper for weekly malware scanner execution from the default deployment path.
- `cron.monthly/lynis-audit`: Wrapper for monthly Lynis execution from the default deployment path.
- `devuan_security_automation.md`: Full workflow, deployment commands, package recommendations, and operational guidance.
- `config/aide/99-local-ignore-dynamic.conf`: Optional AIDE local exclusions for high-churn paths.

## Default Runtime Path

Cron wrappers are configured to execute scripts from `/opt/sysadmin_scripts/security/bin/`.

## Details

For full setup and operational instructions, read `devuan_security_automation.md`.
