Overview
CIS Hardened Image Debian 13 (Level 1) is a production-ready Amazon Machine Image built for organizations that need to deploy secure, compliant Linux workloads on AWS without spending weeks manually applying security controls. This image ships with the CIS Debian Linux 13 Benchmark Level 1 hardening profile already applied, covering hundreds of configuration checks across filesystem permissions, kernel parameters (sysctl), SSH hardening, auditd logging, PAM password policies, service minimization, and secure boot settings. By eliminating the manual hardening process, you reduce the risk of misconfiguration, accelerate time-to-production, and ensure every instance launches from a consistent, auditable security baseline that aligns with industry-recognized CIS Benchmarks.
Beyond baseline hardening, this AMI includes a pre-integrated security and observability stack designed for modern cloud operations. The Wazuh SIEM agent is pre-installed and ready to forward security events, file integrity monitoring (FIM) alerts, and compliance data to your central Wazuh manager, giving you real-time threat detection and host-based intrusion detection out of the box. Nagios monitoring agents provide infrastructure health visibility from the first boot, while pre-configured firewall policies enforce a least-privilege network posture by default. Together, these components deliver defense in depth, continuous compliance monitoring, and operational visibility without requiring additional tooling or manual integration work.
Highlights
- CIS Debian 13 Level 1 Hardening Pre-Applied Ships with the full CIS Debian Linux 13 Benchmark Level 1 profile already configured kernel hardening (sysctl), SSH hardening, auditd, PAM password policies, and service minimization so every instance launches from an audit-ready, secure-by-default baseline.
- Integrated Wazuh SIEM & Nagios Monitoring Includes the Wazuh SIEM agent and Nagios monitoring pre-installed and ready to connect, delivering real-time threat detection, file integrity monitoring (FIM), and infrastructure health visibility from the very first boot.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
- ...
Dimension | Cost/hour |
|---|---|
t2.2xlarge Recommended | $0.07 |
t2.micro | $0.07 |
t3.micro | $0.07 |
r5dn.2xlarge | $0.07 |
r5b.24xlarge | $0.07 |
f1.4xlarge | $0.07 |
r5a.12xlarge | $0.07 |
m4.large | $0.07 |
z1d.2xlarge | $0.07 |
m5ad.4xlarge | $0.07 |
Vendor refund policy
No refunds will be issued for usage of this product.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Debian GNU/Linux 13 Hardened CIS
Additional details
Usage instructions
Once the instance is running, connect to it using a Secure Shell (SSH) client with the configured SSH key. The default username is 'admin'.
Resources
Vendor resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.