The solution goes beyond compliance by offering a Ubuntu server with comprehensive security hardening by default, covering everything from applications to the Linux kernel. With VED threat mitigation, you can rest assured that your digital assets are protected against advanced threats.
Ubuntu is a well-maintained GNU/Linux distribution that is cloud native friendly. Our AMI product features a Ubuntu server with comprehensive security hardening applied by default. By implementing CIS and STIG benchmarks, this product can help you achieve compliance with regulations such as PCI-DSS and GDPR. Here's some basic info about the product:
Ubuntu 22.04, x86_64
Security baselines including CIS and STIG, making compliance integration with your business easy
Wazuh agent for SIEM (Security information and event management) and XDR (Extended detection and response) monitoring
ClamAV anti-virus
AIDE, for file system integrity management
Auditd for monitoring
VED (Vault Exploit Defense), for Linux kernel runtime protection. This feature is designed to protect your digital assets from advanced threats such as 0-day Linux kernel exploits, privilege escalation, container escape, and rootkits.
DNSCrypt-proxy, supporting DNSCrypt relays, local DNS-over-HTTPS, and more.
The current password policy requires changing passwords every 60 days
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for each running instance, with no upfront commitment. Pricing is organized by AWS EC2 instance type, so your rate depends on the compute size you choose. The options span the t2, t3, m4, m5a, and m6i families, from smaller sizes like t2.small and t3.medium up to larger ones like m5a.24xlarge and m6i.32xlarge. Larger instance sizes carry more compute and memory, and the hourly software rate scales with the instance you select. You can run multiple instances and are billed only for the hours each one runs.
Top-of-mind questions for buyers
What security features come with this hardened Ubuntu image regardless of instance size?
Every instance includes CIS/STIG security baselines, VED for Linux kernel runtime protection, AppArmor for mandatory access control, and AIDE for file integrity checks. It also adds SIEM/XDR integration through a monitoring agent. These features protect against kernel exploits, privilege escalation, container escape, and rootkits.
Am I charged when an instance is stopped or paused?
You pay the hourly software rate only while an instance runs. A stopped or paused instance does not accrue software charges. Note that underlying AWS storage fees for the instance may still apply while it sits idle, but the software license meters running hours only.
Does running VED reduce instance performance and add cost?
VED runs inside the image at no separate charge; you pay only the hourly rate for the instance type you pick. VED adds under 1% overhead in CPU-intensive tests, though I/O-intensive workloads can see over 30%. Heavier workloads may need a larger instance size, which raises the hourly rate.
hardenedvault.net+1
Helpful?
Vendor refund policy
We do not support refund but you can feel free to cancel subscription.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
This version has been optimized to accommodate less strict firewall/iptables rules to better support the provision of Docker/container environments. We do not provide rootless mode of Docker due to two reasons: 1) It has higher risk by enabling unprivileged user namespaces. 2) It's user's decision to make. VED can provide some protection even under unprivileged user namespaces is enabled. Additionally, v1.6 now includes support for DNSCrypt to enhance DNS privacy protection.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Configuration adheres to STIG guidelines, which are vendor-neutral standards developed through consensus-based approach and recognized across government, business, industry, and academia.
Attack Surface Minimization
Pre-configured safeguards and security controls are implemented by default to reduce attack surfaces and enhance overall security posture.
Multi-Framework Compliance Foundation
STIG-based configuration serves as a foundation for compliance with multiple cybersecurity frameworks and industry-specific security requirements.
Ubuntu 22.04 Base Operating System
Built on Ubuntu 22.04 Linux distribution as the underlying operating system.
Pre-configured Security Controls
System comes meticulously preconfigured with security controls and hardened configurations to eliminate manual security setup requirements.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.