Listing Thumbnail

    Hardened Ubuntu 22.04 for x86_64

     Info
    Deployed on AWS
    The solution goes beyond compliance by offering a Ubuntu server with comprehensive security hardening by default, covering everything from applications to the Linux kernel. With VED threat mitigation, you can rest assured that your digital assets are protected against advanced threats.

    Overview

    Ubuntu is a well-maintained GNU/Linux distribution that is cloud native friendly. Our AMI product features a Ubuntu server with comprehensive security hardening applied by default. By implementing CIS and STIG benchmarks, this product can help you achieve compliance with regulations such as PCI-DSS and GDPR. Here's some basic info about the product:

    • Ubuntu 22.04, x86_64
    • Security baselines including CIS and STIG, making compliance integration with your business easy
    • Wazuh agent for SIEM (Security information and event management) and XDR (Extended detection and response) monitoring
    • ClamAV anti-virus
    • AIDE, for file system integrity management
    • Auditd for monitoring
    • VED (Vault Exploit Defense), for Linux kernel runtime protection. This feature is designed to protect your digital assets from advanced threats such as 0-day Linux kernel exploits, privilege escalation, container escape, and rootkits.
    • DNSCrypt-proxy, supporting DNSCrypt relays, local DNS-over-HTTPS, and more.
    • The current password policy requires changing passwords every 60 days
    • ETC

    Highlights

    • Security hardening by default.
    • Easily integrate with PCI-DSS/GDPR/ETC compliance
    • Cutting-edged Linux runtime protection

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 22.04

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Hardened Ubuntu 22.04 for x86_64

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (32)

     Info
    Dimension
    Cost/hour
    t3.medium
    Recommended
    $0.05
    m4.xlarge
    $0.05
    t2.large
    $0.05
    m4.10xlarge
    $0.05
    m6i.4xlarge
    $0.05
    m4.2xlarge
    $0.05
    m4.16xlarge
    $0.05
    t3.large
    $0.05
    m6i.8xlarge
    $0.05
    m6i.large
    $0.05

    Vendor refund policy

    We do not support refund but you can feel free to cancel subscription.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    This version has been optimized to accommodate less strict firewall/iptables rules to better support the provision of Docker/container environments. We do not provide rootless mode of Docker due to two reasons: 1) It has higher risk by enabling unprivileged user namespaces. 2) It's user's decision to make. VED can provide some protection even under unprivileged user namespaces is enabled. Additionally, v1.6 now includes support for DNSCrypt to enhance DNS privacy protection.

    Additional details

    Usage instructions

    Usage Instructions: To connect to your instance, you will need to use SSH or standard AWS methods as described: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AccessingInstancesLinux.html 

    1, Update the system to the latest version: #apt update && apt upgrade -y

    2, Please change all passwords Linux system accounts (ubuntu and root via cmd-line "passwd" or "sudo passwd").

    3, VED is loaded at start up by default.

    4, Install Wazuh agent via: ./agent-deployment.sh WAZUH_SERVER_IP_ADDR

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Compliance and Auditing, Operating Systems, Security

    Overview

     Info
    AI generated from product descriptions
    Security Hardening
    Comprehensive security hardening applied by default, implementing CIS and STIG benchmarks
    Threat Mitigation
    VED (Vault Exploit Defense) for Linux kernel runtime protection against advanced threats like 0-day exploits, privilege escalation, and rootkits
    Security Monitoring
    Wazuh agent integrated for SIEM and XDR monitoring with additional security tools like Auditd and ClamAV anti-virus
    Integrity Management
    AIDE file system integrity management with DNSCrypt-proxy supporting DNS-over-HTTPS and relay capabilities
    Compliance Framework
    Pre-configured security baselines enabling integration with regulatory standards like PCI-DSS and GDPR
    Security Hardening
    Pre-configured container image hardened against CIS Benchmarks Level 1 profile with comprehensive security configurations
    Compliance Assessment
    Includes CIS Configuration Assessment Tool (CIS-CAT Pro) reports for demonstrating conformance to security benchmarks
    Benchmark Alignment
    Follows industry-recognized security recommendations developed through consensus-based process by CIS
    Configuration Reporting
    Provides detailed HTML reports and text files documenting system configuration before and after hardening
    Platform Compatibility
    Designed to run on container runtimes and orchestration services like Amazon ECS and Amazon EKS
    Security Configuration
    Preconfigured with Security Technical Implementation Guides (STIG) standards for comprehensive system security
    Attack Surface Reduction
    Engineered with pre-set safeguards and default configurations to minimize potential security vulnerabilities
    Compliance Readiness
    Designed to meet industry-specific security regulations and cybersecurity framework requirements without additional customization
    Operating System Hardening
    Ubuntu 22.04 Linux distribution optimized with enhanced security controls and baseline protections
    Vendor-Neutral Security
    Developed through consensus-based approach with guidelines recognized across government, business, and academic sectors

    Contract

     Info
    Standard contract

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.