systemctl mask sshd

Category: Security & Hardening

systemctl mask sshd

Disable SSH completely

Symlinks the sshd unit to /dev/null, so it cannot be started by any means, including dependencies or manual start attempts. This is the drastic way to shut down SSH after a compromise or on a hardened bastion. Re-enable with systemctl unmask sshd.
Looking for more? Search all 7,657 commands — works offline, in English or Spanish, and fixes typos.