Debian Package a Day ([info]debaday) wrote,
@ 2004-08-27 08:18:00
Previous Entry  Add to memories!  Tell a Friend  Next Entry
samhain - Data integrity and host intrusion alert system
Samhain is an integrity checker and host intrusion detection system that can be used on single hosts as well as large, UNIX-based networks. It supports central monitoring as well as powerful (and new) stealth features to run undetected on memory using steganography.

Main features
  • Complete integrity check

    • uses cryptographic checksums of files to detect modifications,

    • can find rogue SUID executables anywhere on disk, and

  • Centralized monitoring

    • native support for logging to a central server via encrypted and authenticated connections

  • Tamper resistance

    • database and configuration files can be signed

    • logfile entries and e-mail reports are signed

    • support for stealth operation


Homepage: http://la-samhna.de/samhain/index.html

This and many, many other fine package suggestions come from Robert Waldner. Robert adds:
Poor mans tripwire, I'd call it. Also bloody useful for co-adminned systems, because it also functions as a notifier telling you which config-file has just changed. Good companion to running chkrootkit from a trusted boot-environment.

More information on this package can be found on the Debian web site.
(If there is a package you would like to see featured here, go to the userinfo page and follow the directions there to submit your entry.)

Now available in RSS and ATOM flavors too.



(3 comments) - (Post a new comment)

other intergrity checkers
(Anonymous)
2004-08-27 12:16 pm UTC (link)
aide
integrit

both are less featureful than samhain, but possibly simpler to configure and use.

but, sheesh, on a testing or unstable installation, updated daily or so, the output of any integrity checker can bury somebody.

(Reply to this)

Root Kit Hunger
(Anonymous)
2004-08-29 05:06 pm UTC (link)
rkhunter - http://www.rootkit.nl/

(Reply to this)

Root Kit Hunter
(Anonymous)
2004-08-29 05:08 pm UTC (link)
rkhunter - http://www.rootkit.nl/

(Reply to this)


(3 comments) - (Post a new comment)

Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…