Repository navigation
Releases: gentzycode/lordmoritz-fortify
Release list
v2.1.7
Full Changelog: v2.1.6...v2.1.7
v2.1.6
v2.1.5
Full Changelog: v2.1.4...v2.1.5
v2.1.5 - 2025-05-13 22:58 WAT
- Updated version to v2.1.5.
- Documented v2.1.5 features in README: progress spinner, IP restriction for databases, dry run mode, ASCII banner, and version check.
v2.1.4
Full Changelog: v2.1.3...v2.1.4
v2.1.4 - 2025-05-13 22:39 WAT
- Updated README.md to reflect v2.1.4.
- No new functional changes; version bump for documentation update.
v2.1.2
Full Changelog: v2.1.1...v2.1.2
v2.1.2 - 2025-05-13
- Added interactive and unattended firewall port configuration for HTTP, HTTPS, Webmin, mail services, FTP, DNS, MySQL, PostgreSQL, and ICMP.
- Improved logging and summary for UFW rules.
- Added security recommendations for firewall configuration.
v2.1.1
🛡️ Lordmoritz Fortify Script — Release v2.1.1
Author: Chinonso Okoye (Lordmoritz / Gentmorris / Gentzycode)
Release Date: 28 April 2025
License: MIT
✨ What's New in v2.1.1
This release marks a major evolution of the Lordmoritz Fortify Script, introducing self-maintenance capabilities and further refining system hardening for unattended security compliance.
✅ Self-Update Command Introduced:
- Run
sudo lordmoritz-fortify lordmoritz upgrade me - Seamlessly pulls the latest improvements directly from GitHub and updates the script itself.
- No need for manual re-cloning or reinstallation!
✅ Enhanced Usage Detection:
- Clear user guidance when wrong input is provided.
- Fortify (
lordmoritz fortify me) or Upgrade (lordmoritz upgrade me) flows are automatically detected and managed.
✅ Failsafe Git Pull Logic:
- Even if the user’s installation folder gets corrupted or unreachable, upgrade errors are caught gracefully.
✅ Improved Cron Resilience:
- Heavy tasks (AIDE check, nightly ClamAV and rkhunter scans, Fail2Ban maintenance) are scheduled without duplicates.
- Self-healing for Fail2Ban and AIDE remains intact.
✅ Refined Logs and Summaries:
- Security actions, scan results, and warnings are all logged in
/var/log/security-reports/. - Clean summary presented after fortification, including Canonical Livepatch recommendation.
✅ General Codebase Optimization:
- More polished output colors for
[OK],[WARNING],[ERROR]statuses. - Reduced duplicate code, tightened retry mechanisms.
- Future-proofed for smoother packaging as
.debif needed.
⚙️ How to Install
curl -sSL https://raw.githubusercontent.com/gentzycode/lordmoritz-fortify/main/INSTALL.sh | sudo bashFortify your system:
sudo lordmoritz-fortify lordmoritz fortify meUpgrade in the future (no reinstall needed):
sudo lordmoritz-fortify lordmoritz upgrade me📚 Notes
- Designed for Ubuntu 20.04+, 22.04+, and compatible Debian systems.
- Perfect for cloud VMs, bare-metal servers, and security-focused deployments.
- Minimal system load during fortification; heavy scans scheduled for midnight.
- AIDE, ClamAV, rkhunter, Fail2Ban, UFW firewall — all automatically installed, configured, and maintained.
- Optionally, add
--skip-heavy-scansfor lightweight systems.
🏆 Special Credits
- Concept and Engineering: Chinonso Okoye (Lordmoritz / Gentmorris / Gentzycode)
- GitHub Project: [lordmoritz-fortify](https://github.com/gentzycode/lordmoritz-fortify)
🚀 Let Lordmoritz Fortify your Infrastructure!
📢 Release Note: Lordmoritz Fortify v1.0.0
Lordmoritz Fortify v1.0.0
Release Tag: v1.0.0
Overview
Lordmoritz Fortify is a professional-grade automation script for Ubuntu VM security hardening, healing, and monitoring. This is the first public release, delivering a fully unattended, intelligent fortification solution for cloud VMs, production servers, and private infrastructures.
Designed by Chinonso Okoye (Lordmoritz/Gentmorris/Gentzycode) to enable professionals to achieve security compliance and operational resilience without manual intervention.
🚀 Key Features
- Automated Security Tools Installation:
- ClamAV (malware scanning)
- RKHunter (rootkit detection)
- Fail2Ban (intrusion prevention)
- UFW (firewall)
- AIDE (file integrity)
- Unattended-Upgrades (automatic security patches)
- Firewall hardening with UFW and SSH lockdown
- Scheduled nightly security scans (malware, rootkits, filesystem integrity)
- Fail2Ban auto-healing for database corruption
- AIDE database initialization and finalization
- Canonical Livepatch recommendation for zero-downtime kernel patching
- Automatic cron setup without duplicates or conflicts
- Detailed logs at
/var/log/security-reports/
🔥 Improvements Over Internal Versions
- Safe fallback and retries for critical package installations
- Adaptive behavior for low-resource VMs (
--skip-heavy-scansoption) - Modular AIDE configuration for cron-safe initialization
- Color-coded logs for easier review
- Optimized minimal footprint (low system load)
- Automatic UFW/SSH resilience (prevents lockouts)
- Smart AIDE exclusions for volatile directories (
/proc,/sys,/dev)
🛠 Installation & Usage
New Installation
git clone https://github.com/gentzycode/lordmoritz-fortify.git
cd lordmoritz-fortify
bash INSTALL.sh
lordmoritz fortify meUpgrade Existing
- Navigate to your installation directory:
cd /path/to/lordmoritz-fortify- Pull the latest changes:
git pull origin main- Re-run the installer:
bash INSTALL.sh
lordmoritz fortify meMonitoring Logs
tail -f /var/log/security-reports/latest.logView All Commands
lordmoritz --help📋 System Requirements
- Ubuntu 20.04 LTS / 22.04 LTS / newer
- Root privileges
- Minimum 1GB RAM (2GB recommended)
- 10GB disk space
📈 Roadmap (v1.1.0)
- Multi-distro support (Debian, AlmaLinux, Rocky Linux)
- Systemd service monitoring & auto-recovery
- Pre-hardening backup option
- Self-update command:
lordmoritz upgrade me - Enhanced email alerting
- Cloud-init integration
📜 License
MIT License - Free for commercial and personal use.
© 2025 Chinonso Okoye (Lordmoritz/Gentmorris/Gentzycode)
⚠️ Notes
- For production environments, always test in staging first.
- Report issues at GitHub Issues.