[CentOS] Intrusion Detection

Thu Mar 4 22:21:51 UTC 2010
Aleksey Tsalolikhin <atsaloli.tech at gmail.com>

On Thu, Mar 4, 2010 at 2:02 PM, Dan Burkland <dburklan at nmdp.org> wrote:
> Hello all,
>
> I have been exploring the various intrusion detection systems available for the Linux platform and was wondering what ones you all would recommend? I have used AIDE before and while it is extremely easy to setup, it does not support the ability to send alerts as files are changed (allows one to be aware of an intrusion almost immediately).
>
> Thank you,
>
> Dan Burkland


I would use tripwire or Cfengine, run frequently, they can both send
alerts if files get changed.

Best,
-at