Urgent Raspberry Pi Hardening

Job ID: 40548554

Budget: $30 – $250 USD

I am sitting in a hotel with up to three Raspberry Pis on a wired link, sharing the same physical network as known attackers. One board is in normal day-to-day use, another runs Pi-hole with AdGuard; the third may or may not be powered on, but plan for it anyway. I need a security expert who can begin immediately and finish within one hour.

Here is what has to happen during that short window:

• Connect (SSH or other secure method that we agree on) and inventory every installed package.
• Run Mobile Verification Toolkit (mvt) or a comparable scanner to make sure the OS image is free of spyware, rootkits, or back-doored repositories.
• Examine boot-time files (config.txt, cmdline.txt, cron, rc.local, systemd units) to verify nothing unexpected launches.
• Lock down all external management paths; confirm no reverse shells, tunnels, or unknown users exist.
• Configure a strict firewall—iptables or ufw is fine as long as inbound is default-deny and outbound is limited to essential Pi-hole and OS updates.
• Test connectivity with tools like nmap and tcpdump to ensure no rogue traffic leaks once the rules are active.
• Deliver a concise report and the final rule set so I can reproduce the hardening on future boards.

You will have root credentials and I’ll be online the whole time to approve any reboots. Speed, clear communication, and verifiable results are the keys to a successful engagement.