Samhain is a file integrity / intrusion detection system that can be used on single hosts as well as on networks. It been designed to monitor multiple hosts with potentially different operating systems, providing centralized logging and baseline database storage, although it can also be used as standalone application on a single host.
Homepage
Download
Recent Releases
3.1.527 Mar 2015 03:45
major bugfix:
Fix IPv6 issue with portcheck (need to be able to specify
IPv6 interfaces).
Fix minor issues with bugs in testing code
Add command line option '--server-host' to set the log server.
In samhain.startLinux.in start script template, add code to read
options from /etc/sysconfig/ NAME for RedHat.
3.1.417 Feb 2015 18:43
major bugfix:
A bug has been fixed that was introduced in version 3.1.2 and would cause the database initialisation to fail if the configuration asks to check a non-existent file. Also, a problem in handling very large UNIX groups has been fixed, and the detection of the rpmbuild top directory (for 'make rpm') has been improved.
3.1.301 Nov 2014 07:48
minor bugfix:
A potential deadlock in the UNIX entropy gatherer (only used on systems without /dev/(u)random device) has been fixed. Error reporting for an 'update' failure because of a missing local baseline database has been improved.
|