OSSEC HIDS is an Open Source Host-based Intrusion Detection System. It performs log analysis, integrity checking, rootkit detection, time-based alerting and active response.
It runs on most operating systems, including Linux, OpenBSD, FreeBSD, Solaris and Windows.
This is the first version offering native support for Windows (XP/2000/2003). It includes as well a new set of log analysis rules for sendmail, web logs (Apache and IIS), IDSs and Windows authentication events.
The correlation rules for squid, mail logs, firewall events and authentication systems have been improved, now detecting scans, worms and internal attacks.
The active-responses were also refined, with support to IPFW (FreeBSD) added.
The installation process was re-organized, now including simpler configuration options and
translation on 6 different languages (English, Portuguese, German, Turkish, Polish and Italian).
Stored in: Countermeasures, Security Software
Related Posts:
- Impressive Open Source Intrusion Prevention - HLBR
- .NETIDS - .NET Intrusion Detection System
- stealth techniques - syn
- PHPIDS - Security Layer & Intrusion Detection for PHP Based Web Applications
- Custom Trojans - Isn’t it Old News?
- IPAudit - Network Activity Monitor with Web Interface
| 4,909 views |


