{"id":5381,"date":"2023-08-31T23:12:57","date_gmt":"2023-08-31T15:12:57","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=5381"},"modified":"2023-08-31T23:13:48","modified_gmt":"2023-08-31T15:13:48","slug":"agentsmith-hids-host-based-intrusion-detection","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2023\/08\/agentsmith-hids-host-based-intrusion-detection\/","title":{"rendered":"AgentSmith HIDS – Host Based Intrusion Detection"},"content":{"rendered":"\n

AgentSmith HIDS is a powerful component of a Host-based Intrusion Detection system, it has anti-rootkit functionalities and is a very performant way to collect information about a host.<\/p>\n\n\n\n

\"\"<\/figure>\n\n\n\n

Technically, AgentSmith-HIDS is not a Host-based Intrusion Detection System (HIDS) due to a lack of a rule engine and detection function. However, it can be used as a high-performance ‘Host Information Collect Agent’ as part of your own HIDS solution. The comprehensiveness of information that this agent can collect was one of the most important metrics during development of this project, hence it was built to function in the kernel stack and achieve huge advantages compared to those functions in the user stack, such as:<\/p>\n\n\n\n