AIDE (free tripwire-like) http://www.cs.tut.fi/~ramm
Main Topics
Browse All TopicsI am looking for a Tool which can do the auditing for different servers (windows/Unix) in network for any kind of security breach or unauthorized changes. It should also compare the file structures/permission and modified date for data/application available on different Boxes.
I have heard about some tools like DumpSec /OSIRIS, please share some better options on it.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
AIDE (free tripwire-like) http://www.cs.tut.fi/~ramm
There's some info here: http://en.wikipedia.org/wi
If you opt for the opensource Tripwire, there's an easy migration path to the commercial version, if you need the GUI / reporting functions: http://sourceforge.net/pro
I am looking for a tool which can provide the information about file changes/deletion, Group/user permission changes so better to get a customized tool where we can get the detail like timestamp for specific file/folders when it was changed last time and who has done these changes&?
anyone tried OSISRIS tool..?
there are many tools available like nmap, nessus, MBSA. Some of the links are provided here -
http://sectools.org/
http://sectools.org/web-sc
http://insecure.org/
http://nmap.org/
http://www.gfi.com/lannets
http://www.f-secure.com/en
some of these tools are free and others have evaluation versions available.
Macafee and symantec also have some free tools available on their website.
please check this out -
http://www.symantec.com/bu
http://www.mcafee.com/us/e
http://www.mcafee.com/us/e
http://home.mcafee.com/sto
http://symantec-w32-downad
i never used Professional Audit Expander v4.0.. so no comments on that :)
for wmi scripts, you can use Microsoft's scriptcenter. following sites are also useful -
http://www.microsoft.com/d
http://techrepublic.com.co
http://www.codeproject.com
Thanks a lot for sharing all the stuff.
will anyone please help me to configure OSIRIS or can anyone provode any doc for Osiris configuartion
for linux/windows..?
As there is limited information given on website.
Please share the doc if any for Osiris configuartion and alos confirm about the usage/fetaures fo osiris in windows/linux..!
Hi,
None of the tools mentioned here would do what you want. What you are looking for is called "Host Integrity Monitors" not the general "vulnerability scanners" such as NMAP or Nessus.
So you'd better need to reformulate the question. What you need is a tool like OSIRIS or Samhain. Here's an article in security focus comparing these applications.
OSIRIS offers large platform support like Windows and Several Unices and SAMHAIN supports yet a broader line of commercial Unices. OSIRIS supports modules and could monitor kernels too while smahain supports digital ly signed detection libraries which are more immune to tampering ..
Please read the article then let's elaborate on the issue further.
Cheers,
K.
Opps sorry I'Ve forgooten to present the link:
http://www.securityfocus.c
Thanks ,I agree with you.
this will be a gret help for me if i can get the deployemnet doc for Osiris configuartion or any other better tool.
My requirement is:
I am looking for a Tool which can do the auditing for different servers (windows/Unix) in network for any kind of security breach or unauthorized changes. It should also compare the file structures/permission and modified date for data/application available on different Boxes
Dear Briejeshk9,
As you can see from the articke Osiris supports both Windows and several Unices including Linux, Hp-UX, MAC OS X. What it does is to compare file permissions etc on the server it is running on.
however what you want is to gather data from different systems and compare them to each other I doubt that you can do it only one software. Companies doing these type of audit works have a repository of programs ans some customized scripts to create a comparative audit data for that matters.
So there's no single ultimate tool to do what you need around. You need to gget data and export it and do necessary tabulation with other tools and even office Automation programs such as a general Purpose SpreadSheet program or a word processor, databases and scripts to interpret or compare, colalte and interpret the findings.
This is called an IT Audit and usually performed as a part of the Internal Audit process. This type of activity generally planned in advance and well documented including expected results before the beginning and some suggestions for improvement in the light of interpreted data.
Cheers,
K.
Business Accounts
Answer for Membership
by: Brijeshk9Posted on 2009-08-19 at 22:57:31ID: 25139638
m also looking for help doc on osiris..!