We’ve only mentioned one HIDS before, that was OSSEC HIDS, so I thought I’d do some updates on the others.
Samhain has always been one of my favourites, before that of course I was using Tripwire like everyone else.
The Samhain open source host-based intrusion detection system (HIDS) provides file integrity checking and logfile monitoring/analysis, as well as rootkit detection, port monitoring, detection of rogue SUID executables, and hidden processes.
It has been designed to monitor multiple hosts with potentially different operating systems, providing centralized logging and maintenance, although it can also be used as standalone application on a single host.
Samhain is a multiplatform application for POSIX systems (Unix, Linux, Cygwin/Windows).
Features
- PCI DSS Compliance
- File integrity checks
- Host integrity monitoring
- Logfile monitoring/analysis
- Log facilities
- Integration with other systems / Active response
You can download Samhain here:
Or read more here.
Stored in: Countermeasures, Security Software
Related Posts:
- OSSEC HIDS – Open Source Host-based Intrusion System
- .NETIDS – .NET Intrusion Detection System
- Impressive Open Source Intrusion Prevention – HLBR
- psad – Intrusion Detection and Log Analysis with iptables
- PHPIDS – Security Layer & Intrusion Detection for PHP Based Web Applications
- Viruses & Malware Monitored on a Dynamic World Map
| 23,044 views |


