Revision [3804]
Last edited on 2010-08-19 07:53:57 by KenFongAdditions:
===Host based IDE===
[[AIDE IdsAIDE]]
[[OSSEC IdsOSSEC]]
[[AIDE IdsAIDE]]
[[OSSEC IdsOSSEC]]
Revision [1034]
Edited on 2007-10-16 20:26:43 by WikiAdminAdditions:
Download AIDE from sourceforge and do a source install. configure will tell you libgpg-error-devel, bison and flex are required if not already installed.
Deletions:
Revision [844]
Edited on 2007-08-07 00:53:24 by WikiAdminAdditions:
Schedule check via crontab
01 * * * * root aide --check || mutt -s AIDE_WARN_hostname someone@somewhere.com < /var/log/aide.out
01 * * * * root aide --check || mutt -s AIDE_WARN_hostname someone@somewhere.com < /var/log/aide.out
Revision [843]
Edited on 2007-08-07 00:46:43 by WikiAdminNo differences.
Revision [842]
Edited on 2007-08-07 00:45:25 by WikiAdminAdditions:
less /var/log/aide.out
Revision [841]
Edited on 2007-08-07 00:44:20 by WikiAdminAdditions:
==Usage==
First initialize the database
aide --init
cp /var/lib/aide.db.new /var/lib/aide.db
Check for changes
aide --check
Update database
aide --update
First initialize the database
aide --init
cp /var/lib/aide.db.new /var/lib/aide.db
Check for changes
aide --check
Update database
aide --update