A few years back, I was charged by my boss to come up with something similar
for AIX.

The problem that quickly occurred to me is the trick isn't to detect changed
files, the problem is to figure out which changed files are noteworthy, and
which are "yeah, that happens many times a second".  I quickly gave up on a
completely automated approach, and figured, "ok, we are going to have to
ignore changes for certain files, certain file types, and certain directories,
then show the administrators the things that CAN'T be explained, and let them
decide if they were significant".

So...  I have two tools:
1) Incremental Backup System -- backs up systems, using rsync --link-dest and
writes a report of all new or changed files to a report file.
  https://holland-consulting.net/scripts/ibs/
(requires ssh and rsync on the clients and backup server)

2) File Alteration Reporting Tool -- parses the IBS report, removing the files
where changes are expected, and leaving the once for humans to look over.
  https://holland-consulting.net/scripts/ibs/fart.html
(all shell script and standard Unix tools)

At my job, we had the on-call person and the previously on-call person look at
the reports, and "respond all" to the team what they thought of anything that
FART had flagged.  Those two people were responsible for inspecting the reports
(normally only took a few minute -- most of the changes were of obvious cause,
unless there was something "interesting" that begged for further investigation).

Now...one thing I learned from OpenBSD is that a "security tool" that never
shows anything wrong is probably not really serving you well.  I found the FART
reports QUITE fascinating and far more useful than I ever dreamed.  We found our
software vendor was sometimes logging in and making changes or looking at 
things,
sometimes without notifying us, and sometimes forgetting to delete their tools.
(grabbed copies!!).  We found admins making changes that weren't properly
discussed and would have impacts they hadn't realized.  So yes -- good tool,
something I use myself.

(and yes, while the original version of the File Alteration Reporting Tool was
written for an employer, I have since left that employer, and re-wrote it from
scratch -- which produced far less bad code. :) And we didn't the current name
in the office environment).

Nick.

On 10/6/26 03:48, Carlos Lopez wrote:
Hi all,

I would like to keep my OpenBSD virtual machines monitored with HIDS and file 
integrity opensource solutions. My plan is to use solutions that are as closely 
aligned with OpenBSD as possible.
I’ve been looking into solutions such as Wazuh or Samhain … the idea is to use 
what these tools offer …

Any recommendations? Or could I even do it using OpenBSD’s own tools?

Best regards,
C. L. Martinez

Reply via email to