Samhain (software)
Appearance
This article has multiple issues. Please help improve it or discuss these issues on the talk page. (Learn how and when to remove these messages)
|
Developer(s) | Samhain Services |
---|---|
Stable release | 4.2.1
/ April 6, 2017[1] |
Written in | C[2] |
Operating system | Linux, all POSIX/UNIX Systems |
Type | Security, Monitoring, HIDS |
License | GNU General Public License |
Website | la-samhna.de/samhain |
Samhain is an integrity checker and host intrusion detection system that can be used on single hosts as well as large, UNIX-based networks. It supports central monitoring as well as powerful (and new) stealth features to run undetected in memory, using steganography.
Main features
- Complete integrity check
- uses cryptographic checksums of files to detect modifications,
- can find rogue SUID executables anywhere on disk, and
- Centralized monitoring
- native support for logging to a central server via encrypted and authenticated connections
- Tamper resistance
- database and configuration files can be signed
- log file entries and e-mail reports are signed
- support for stealth operation
References
- ^ "archive". Retrieved 15 June 2017.
- ^ "files for revision 17". Launchpad.net. Retrieved 15 June 2017.
See also
External links