[CentOS] Intrusion Detection

Thu Mar 4 22:18:25 UTC 2010
Jim Perrin <jperrin at gmail.com>

On Thu, Mar 4, 2010 at 5:02 PM, Dan Burkland <dburklan at nmdp.org> wrote:
> Hello all,
>
> I have been exploring the various intrusion detection systems available for the Linux platform and was wondering what ones you all would recommend? I have used AIDE before and while it is extremely easy to setup, it does not support the ability to send alerts as files are changed (allows one to be aware of an intrusion almost immediately).


You can use auditd to watch specific files if you're after some key
things. Beyond that I just use aide.


-- 
During times of universal deceit, telling the truth becomes a revolutionary act.
George Orwell