[SAMHAIN 3.0.9] File Integrity Checker / Host-Based Intrusion Detection System
The Samhain
host-based intrusion detection system (HIDS) provides
file integrity checking
and log file monitoring/analysis,
as well as rootkit detection, port monitoring, detection of rogue
SUID executables, and hidden processes.
Samhain been designed to monitor multiple hosts
with potentially different operating systems, providing
centralized logging and maintenance,
although it can also be used as standalone application on a single
host.
Samhain is an open-source multiplatform application for POSIX systems
(Unix, Linux, Cygwin/Windows).
Samhain is a file system integrity checker that
can be used as a client/server application for centralized monitoring of
networked hosts. Databases and configuration files can be stored on the
server. Databases, logs, and config files can be signed for tamper
resistance. In addition to forwarding reports to the log server via
authenticated TCP/IP connections, several other logging facilities
(e-mail, console, and syslog) are available. Tested on Linux, AIX,
HP-UX, Unixware, Sun and Solaris.
Changes: Some build errors have been
fixed, as well as the 'probe' command for the server (clients could be
erroneously omitted under certain conditions). An option has been added
to the Windows registry check to ignore changes if only the timestamp
has changed, and full scans requested by the inotify module will now
only run at times configured for regular full scans.
[SAMHAIN 3.0.9] File Integrity Checker / Host-Based Intrusion Detection System
Reviewed by Zion3R
on
4:20 PM
Rating: