Revision as of 14:27, 19 October 2017 edit98.6.18.132 (talk) OSSEC supports Debian based systems← Previous edit |
Latest revision as of 23:23, 11 August 2024 edit undo66.41.189.188 (talk) →Free and open-source software |
(48 intermediate revisions by 30 users not shown) |
Line 1: |
Line 1: |
|
Comparison of ] components and systems. |
|
Comparison of ] components and systems. |
|
|
|
|
|
==]== |
|
==]== |
|
As per the ] a good HIDS is composed of multiple packages each focusing on a specific aspect. |
|
As per the ] a good HIDS is composed of multiple packages each focusing on a specific aspect. |
|
{| class="wikitable sortable" |
|
{| class="wikitable sortable" |
|
|- |
|
|- |
|
! Package |
|
! Package |
|
|
! Updated |
|
! Year<ref>Last updated</ref> |
|
|
! Ubuntu<ref>Repositories</ref> |
|
! Ubuntu <small>Official Repositories</small> |
|
! CentOS<ref>Repositories</ref> |
|
! CentOS <small>Official Repositories</small> |
|
|
! ] <small>Official Repositories</small> |
|
! File |
|
! File |
|
! Network |
|
! Network |
|
! Logs |
|
! Logs |
|
! ] |
|
! ] |
|
! Sane defaults |
|
|
! Notes |
|
! Notes |
|
|- |
|
|- |
|
| ] |
|
| ] |
|
| 2017 |
|
| 2022 |
|
⚫ |
| {{no}}<ref>{{cite web |url=https://ossec.github.io/downloads.html#apt-automated-installation-on-ubuntu-and-debian |title=Downloads OSSEC|publisher=OSSEC|accessdate=2017-10-19 }} OSSEC for Debian Based systems</ref> |
|
|
| {{no}}<ref>{{cite web |url=https://ossec.github.io/downloads.html#rhel-centos-fedora-and-others |title=Downloads OSSEC|publisher=OSSEC|accessdate=2017-10-29 }} OSSEC for RHEL/Fedora Based systems</ref> |
|
|
| {{yes}}<ref>{{cite web |url=https://software.opensuse.org/package/ossec-hids |title=ossec-hids|publisher=openSUSE OBS|accessdate=2024-08-11 }} An Open Source Host-based Intrusion Detection System </ref> |
|
| {{yes}} |
|
| {{yes}} |
|
⚫ |
| {{yes}} |
|
⚫ |
| {{yes}} |
|
⚫ |
| {{yes}} |
|
⚫ |
| |
|
⚫ |
|- |
|
|
|Wazuh |
|
|
|2022 |
|
| {{no}} |
|
| {{no}} |
|
⚫ |
| {{no}} |
|
⚫ |
| ? |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| |
|
| |
⚫ |
| |
|
|
|- |
|
|- |
|
| ] |
|
| ] |
|
| 2016 |
|
| 2021 |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=samhain |title=Samhain |publisher=Ubuntu |accessdate=2017-04-19 }} Samhain in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=samhain |title=Samhain |publisher=Ubuntu |accessdate=2017-04-19 }} Samhain in the Ubuntu Repositories</ref> |
|
| {{no}} |
|
| {{no}} |
|
|
| {{yes}}<ref>{{cite web |url=https://software.opensuse.org/package/samhain?search_term=Samhain |title=Samhain |publisher=openSUSE OBS|accessdate=2024-08-11 }} File integrity and host-based IDS</ref> |
|
| {{yes}} |
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{partial}}<ref>Last</ref> |
|
| {{partial}}<ref>Last</ref> |
|
| |
|
| |
⚫ |
| {{no}} |
|
|
| |
|
| |
|
|- |
|
|- |
|
| ] |
|
| ] |
|
| 2015 |
|
| 2018 |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=snort |title=Snort |publisher=Ubuntu |accessdate=2017-04-19 }} Snort in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=snort |title=Snort |publisher=Ubuntu |accessdate=2017-04-19 }} Snort in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/snort |title=Snort |publisher=Cisco Systems |accessdate=2017-05-31 }} Snort in the CentOS Repositories</ref> |
|
| {{no}}<ref>{{cite web |url=https://pkgs.org/download/snort |title=Snort |publisher=Cisco Systems |accessdate=2017-05-31 }} Snort in the CentOS Repositories</ref> |
|
⚫ |
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| |
|
| |
⚫ |
| |
|
|
| |
|
| |
|
|- |
|
|- |
|
| ] |
|
| ] |
|
| 2017 |
|
| 2023 |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=chkrootkit |title=ChkRootkit |publisher=Ubuntu |accessdate=2017-04-19 }} ChkRootkit in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=chkrootkit |title=ChkRootkit |publisher=Ubuntu |accessdate=2017-04-19 }} ChkRootkit in the Ubuntu Repositories</ref> |
|
| {{no}} |
|
| {{no}} |
|
⚫ |
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{partial}}<ref>lastlog, wtmp, utmp, wtmpx</ref> |
|
| {{partial}}<ref>lastlog, wtmp, utmp, wtmpx</ref> |
|
| |
|
| |
⚫ |
| |
|
|
| |
|
| |
|
|- |
|
|- |
|
| ] |
|
| ] |
|
| 2014 |
|
| 2018 |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the CentOS Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/rkhunter |title=RKHunter |publisher=Ubuntu |accessdate=2017-04-19 }} RKHunter in the CentOS Repositories</ref> |
|
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
⚫ |
| {{yes}} |
|
|
| {{yes}} |
|
| {{yes}} |
|
| |
|
| |
Line 75: |
Line 86: |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the CentOS Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/unhide |title=UnHide |publisher=Ubuntu |accessdate=2017-04-19 }} UnHide in the CentOS Repositories</ref> |
|
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| |
|
| |
⚫ |
| |
|
|
| proc ps compare |
|
| proc ps compare |
|
|- |
|
|- |
|
| ] |
|
| ] |
|
| 2017 |
|
| 2017 |
|
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
Line 90: |
Line 102: |
|
| {{no}} |
|
| {{no}} |
|
| |
|
| |
⚫ |
| |
|
|
| |
|
| |
|
|- |
|
|- |
Line 97: |
Line 108: |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the CentOS Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logwatch |title=LogWatch |publisher=Ubuntu |accessdate=2017-04-19 }} LogWatch in the CentOS Repositories</ref> |
|
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{yes}} |
|
| {{yes}} |
|
| |
|
| |
⚫ |
| {{no}} |
|
|
| |
|
| |
|
|- |
|
|- |
Line 108: |
Line 119: |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the CentOS Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/logcheck |title=Logcheck |publisher=Ubuntu |accessdate=2017-04-19 }} Logcheck in the CentOS Repositories</ref> |
|
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{yes}} |
|
| {{yes}} |
|
| |
|
| |
⚫ |
| {{no}} |
|
|
| |
|
| |
|
|- |
|
|- |
Line 119: |
Line 130: |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the CentOS Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/epylog |title=Epylog |publisher=Ubuntu |accessdate=2017-04-19 }} Epylog in the CentOS Repositories</ref> |
|
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{yes}} |
|
| {{yes}} |
⚫ |
| |
|
|
| |
|
| |
|
| |
|
| |
Line 130: |
Line 141: |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the CentOS Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/swatch |title=SWATCH |publisher=Ubuntu |accessdate=2017-04-19 }} SWATCH in the CentOS Repositories</ref> |
|
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{yes}} |
|
| {{yes}} |
|
| |
|
| |
|
| |
|
|
| |
|
| |
|
|- |
|
|- |
|
| ] |
|
| ] |
|
| 2017 |
|
| 2021 |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=sagan |title=Sagan |publisher=Ubuntu |accessdate=2017-04-19 }} Sagan in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=sagan |title=Sagan |publisher=Ubuntu |accessdate=2017-04-19 }} Sagan in the Ubuntu Repositories</ref> |
|
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
Line 145: |
Line 157: |
|
| {{yes}} |
|
| {{yes}} |
|
| |
|
| |
|
| |
|
|
| |
|
| |
|
|- |
|
|- |
|
| ] |
|
| ] |
|
| 2016 |
|
| 2023 |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the CentOS Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/aide |title=AIDE |publisher=Ubuntu |accessdate=2017-04-19 }} AIDE in the CentOS Repositories</ref> |
|
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| |
|
| |
⚫ |
| {{no}} |
|
|
| |
|
| |
|
|- |
|
|- |
|
| ] |
|
| ] |
|
| 2013 |
|
| 2018 |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the Ubuntu Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the CentOS Repositories</ref> |
|
| {{yes}}<ref>{{cite web |url=https://pkgs.org/download/tripwire |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the CentOS Repositories</ref> |
|
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| {{no}} |
|
| |
|
| |
|
| |
|
|
| |
|
| |
|
⚫ |
|- |
|
|
| ] |
|
|
| 2018 |
|
|
| {{yes}}<ref>{{cite web |url=http://packages.ubuntu.com/search?keywords=tiger |title=Tripwire |publisher=Ubuntu |accessdate=2017-04-19 }} Tripwire in the Ubuntu Repositories</ref> |
|
|
| {{no}} |
|
|
| {{no}} |
|
|
| {{yes}} |
|
|
| {{no}} |
|
|
| {{no}} |
|
|
| {{yes}} |
|
|
| 3/42 modules are Debian specific. |
|
|- |
|
|- |
|
|} |
|
|} |
Line 185: |
Line 207: |
|
! Notes |
|
! Notes |
|
|- |
|
|- |
|
| |
|
| |
|
| 2017 |
|
| 2018 |
⚫ |
| {{yes}} |
|
|
| {{yes}} |
|
| {{yes}} |
|
|
| {{no}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
Line 195: |
Line 217: |
|
| |
|
| |
|
|- |
|
|- |
|
| ] |
|
| Verisys |
|
| 2016 |
|
| 2018 |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| {{yes}} |
|
| |
|
| |
|
| |
|
| {{yes}} |
|
| |
|
|
| |
|
|
| |
|
| |
|
|- |
|
|- |
Line 214: |
Line 236: |
|
| {{yes}} |
|
| {{yes}} |
|
| |
|
| |
|
⚫ |
|- |
|
|
| |
|
|
|2019 |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
|
|Commercially enhanced version of OSSEC |
|
⚫ |
|- |
|
|
| |
|
|
|2021 |
|
|
| {{no}} |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
|
| {{yes}} |
|
|
|Websocket API, IP to Country mapping, DynDNS Integration |
|
|} |
|
|} |
|
|
|
|
Line 224: |
Line 266: |
|
* |
|
* |
|
* |
|
* |
⚫ |
* |
|
|
|
|
|
|
|
|
|