06 October 2009 | 25,870 views

Samhain v.2.5.9c – Open Source Host-Based Intrusion Detection System (HIDS)

Want to Learn Penetration Testing

We’ve only mentioned one HIDS before, that was OSSEC HIDS, so I thought I’d do some updates on the others.

Samhain has always been one of my favourites, before that of course I was using Tripwire like everyone else.

The Samhain open source host-based intrusion detection system (HIDS) provides file integrity checking and logfile monitoring/analysis, as well as rootkit detection, port monitoring, detection of rogue SUID executables, and hidden processes.

It has been designed to monitor multiple hosts with potentially different operating systems, providing centralized logging and maintenance, although it can also be used as standalone application on a single host.

Samhain is a multiplatform application for POSIX systems (Unix, Linux, Cygwin/Windows).

Features

  • PCI DSS Compliance
  • File integrity checks
  • Host integrity monitoring
  • Logfile monitoring/analysis
  • Log facilities
  • Integration with other systems / Active response

You can download Samhain here:

samhain-current.tar.gz

Or read more here.

Post to Twitter Post to Facebook Post to Google Buzz Post to Delicious Post to Digg Post to Reddit Post to StumbleUpon






Recent in Countermeasures:
- No BEAST Fix From Microsoft In December Patch Tuesday – But They Fixed Duqu Bug
- sslyze – Fast and Full-Featured SSL Configuration Scanner
- Twitter Purchases WhisperCore – Full Disk Encryption For Android Phones

Related Posts:
- OSSEC HIDS – Open Source Host-based Intrusion System
- Suricata – Open Source Next Generation Intrusion Detection and Prevention Engine
- .NETIDS – .NET Intrusion Detection System

Most Read in Countermeasures:
- AJAX: Is your application secure enough? - 115,583 views
- Password Hasher Firefox Extension - 110,123 views
- NDR or Backscatter Spam – How Non Delivery Reports Become a Nuisance - 55,171 views

Advertise on Darknet


Comments are closed.