The solution goes beyond compliance by offering a Ubuntu server with comprehensive security hardening by default, covering everything from applications to the Linux kernel. With VED threat mitigation, you can rest assured that your digital assets are protected against advanced threats.
Ubuntu is a well-maintained GNU/Linux distribution that is cloud native friendly. Our AMI product features a Ubuntu server with comprehensive security hardening applied by default. By implementing CIS and STIG benchmarks, this product can help you achieve compliance with regulations such as PCI-DSS and GDPR. Here's some basic info about the product:
Ubuntu 22.04, x86_64
Security baselines including CIS and STIG, making compliance integration with your business easy
Wazuh agent for SIEM (Security information and event management) and XDR (Extended detection and response) monitoring
ClamAV anti-virus
AIDE, for file system integrity management
Auditd for monitoring
VED (Vault Exploit Defense), for Linux kernel runtime protection. This feature is designed to protect your digital assets from advanced threats such as 0-day Linux kernel exploits, privilege escalation, container escape, and rootkits.
DNSCrypt-proxy, supporting DNSCrypt relays, local DNS-over-HTTPS, and more.
The current password policy requires changing passwords every 60 days
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for each running instance of this hardened Ubuntu image. Pricing follows the EC2 instance type you launch, not a set of feature tiers. The dimensions cover two instance families: the t2 and t3 burstable types (small through 2xlarge) and the m4, m5a, and m6i general-purpose types (large through 32xlarge). Larger sizes carry more CPU and memory, so the hourly rate scales with the instance size you choose. All sizes deliver the same hardened software; you select based on your compute needs and stop charges when you stop the instance.
Top-of-mind questions for buyers
What does the hourly rate cover, and am I charged when the instance is stopped?
The rate covers the hardened Ubuntu software license for each running instance, billed per hour by EC2 instance type. Fully stopped instances stop accruing software charges. You may still pay underlying AWS storage fees for stopped instances, but the software meter counts running time only.
What security features are included in the hardened image I pay for?
Every instance includes CIS/STIG compliance baselines and kernel runtime protection against exploits, privilege escalation, container escape, and rootkits. It also adds mandatory access control, file integrity checking, and integration with security monitoring agents. The same hardened software ships across all instance sizes.
Why does cost differ between the t-series and m-series instance types?
The hourly software rate maps to the EC2 instance type you launch. The t2 and t3 burstable types suit variable, lower-baseline workloads. The m4, m5a, and m6i general-purpose types provide steady CPU and memory. Larger sizes carry more resources, so the rate scales with the size you pick.
hardenedvault.net+1
Helpful?
Vendor refund policy
We do not support refund but you can feel free to cancel subscription.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
This version has been optimized to accommodate less strict firewall/iptables rules to better support the provision of Docker/container environments. We do not provide rootless mode of Docker due to two reasons: 1) It has higher risk by enabling unprivileged user namespaces. 2) It's user's decision to make. VED can provide some protection even under unprivileged user namespaces is enabled. Additionally, v1.6 now includes support for DNSCrypt to enhance DNS privacy protection.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Configuration adheres to STIG guidelines, which are vendor-neutral standards developed through consensus-based approach and recognized across government, business, industry, and academia.
Attack Surface Minimization
Pre-configured safeguards and security controls are implemented by default to reduce attack surfaces and enhance overall security posture.
Multi-Framework Compliance Foundation
STIG-based configuration serves as a foundation for compliance with multiple cybersecurity frameworks and industry-specific security requirements.
Ubuntu 22.04 Base Operating System
Built on Ubuntu 22.04 Linux distribution as the underlying operating system.
Pre-configured Security Controls
System comes meticulously preconfigured with security controls and hardened configurations to eliminate manual security setup requirements.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.