Hello, > On 6 Oct 2026, at 10:48 AM, Carlos Lopez <[email protected]> wrote: > > Hi all, > > I would like to keep my OpenBSD virtual machines monitored with HIDS and file > integrity opensource solutions. My plan is to use solutions that are as > closely aligned with OpenBSD as possible. > I’ve been looking into solutions such as Wazuh or Samhain … the idea is to > use what these tools offer … > > Any recommendations? Or could I even do it using OpenBSD’s own tools?
Before installing something as involved, try configuring the SMTPd to forward root emails to your inbox and look at the daily “insecurity output” which is answers exactly that question. You can learn more about it here: - https://man.openbsd.org/security.8 - https://myunix.org/bsd/openbsd-daily-mail/ Here is an excerpt I received a while back: ``` Running security(8): Checking the /etc/master.passwd file: Login deploy is off but still has a valid shell and alternate access files in home directory are still readable. Checking special files and directories. Output format is: filename: criteria (shouldbe, reallyis) etc/relayd.conf: permissions (0600, 0644) mtree special: exit code 2 ====== /etc/httpd.conf diffs (-OLD +NEW) ====== --- /var/backups/etc_httpd.conf.current Tue Sep 15 01:30:14 2026 +++ /etc/httpd.conf Fri Sep 18 21:27:41 2026 @@ -4,39 +4,35 @@ prefork 5 server “vm28.example.com" { - listen on * port 80 + listen on 127.0.0.1 port 8081 + log style forwarded location "/.well-known/acme-challenge/*" { root "/acme" request strip 2 } - location * { - block return 301 "https://$SERVER_NAME$REQUEST_URI" + location "/*" { + block return 301 "https://$HTTP_HOST$REQUEST_URI" } } ``` Kind regards, P.

