Samhain is a daemon that can check the integrity of files, search the file tree for suid files, and detect kernel modules http://www.aliyun.com/zixun/aggregation/16938.html "> Rootkit (Linux only). It can be used for both stand-alone and centralized monitoring of client/server systems, strong (192-bit AES) encrypted client/server connections and options for databases and configuration files stored on the server. Prevent tampering, it supports signing the database/configuration file and signing the report/audit log. It has passed tests on Linux,freebsd,solaris,aix,hp-ux and UnixWare.
Samhain 2.8.6 The errors of entries in this version and the associated monitored log files have been fixed and a stop time option added to avoid duplicate reports. In verbose mode, the circumstances under which a directory or file is monitored will be escalated. Updated enhancements and updating the files listed in a text file have only one option, and some compilation options have been fixed.
Download Address:
Version 2.8.6 samhain-current.tar.gz MD5 checksum d02494e7282809e76b83fa1c2ecb952b bytes 2075621 release date Sep 30, 2011