A few years back, I was charged by my boss to come up with something similar for AIX.
The problem that quickly occurred to me is the trick isn't to detect changed files, the problem is to figure out which changed files are noteworthy, and which are "yeah, that happens many times a second". I quickly gave up on a completely automated approach, and figured, "ok, we are going to have to ignore changes for certain files, certain file types, and certain directories, then show the administrators the things that CAN'T be explained, and let them decide if they were significant". So... I have two tools: 1) Incremental Backup System -- backs up systems, using rsync --link-dest and writes a report of all new or changed files to a report file. https://holland-consulting.net/scripts/ibs/ (requires ssh and rsync on the clients and backup server) 2) File Alteration Reporting Tool -- parses the IBS report, removing the files where changes are expected, and leaving the once for humans to look over. https://holland-consulting.net/scripts/ibs/fart.html (all shell script and standard Unix tools) At my job, we had the on-call person and the previously on-call person look at the reports, and "respond all" to the team what they thought of anything that FART had flagged. Those two people were responsible for inspecting the reports (normally only took a few minute -- most of the changes were of obvious cause, unless there was something "interesting" that begged for further investigation). Now...one thing I learned from OpenBSD is that a "security tool" that never shows anything wrong is probably not really serving you well. I found the FART reports QUITE fascinating and far more useful than I ever dreamed. We found our software vendor was sometimes logging in and making changes or looking at things, sometimes without notifying us, and sometimes forgetting to delete their tools. (grabbed copies!!). We found admins making changes that weren't properly discussed and would have impacts they hadn't realized. So yes -- good tool, something I use myself. (and yes, while the original version of the File Alteration Reporting Tool was written for an employer, I have since left that employer, and re-wrote it from scratch -- which produced far less bad code. :) And we didn't the current name in the office environment). Nick. On 10/6/26 03:48, Carlos Lopez wrote:
Hi all, I would like to keep my OpenBSD virtual machines monitored with HIDS and file integrity opensource solutions. My plan is to use solutions that are as closely aligned with OpenBSD as possible. I’ve been looking into solutions such as Wazuh or Samhain … the idea is to use what these tools offer … Any recommendations? Or could I even do it using OpenBSD’s own tools? Best regards, C. L. Martinez

