Comparison of host-based intrusion detection system components and systems.
Free and open-source software
As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.
Package | Updated | Ubuntu Official Repositories | CentOS Official Repositories | openSUSE Official Repositories | File | Network | Logs | Config | Notes |
---|---|---|---|---|---|---|---|---|---|
OSSEC | 2025 | No1 | No2 | Yes3 | Yes | Yes | Yes | Yes | |
Wazuh | 2022 | No | No | ? | Yes | Yes | Yes | Yes | |
Samhain | 2023 | Yes4 | No | Yes5 | Yes | No | Partial6 | ||
Snort | 2021 | Yes7 | No8 | No | No | Yes | No | ||
chkrootkit | 2023 | Yes9 | No | Yes | Yes | No | Partial10 | ||
rkhunter | 2018 | Yes11 | Yes12 | Yes | Yes | No | No | Yes | |
unhide13 | 2012 | Yes14 | Yes15 | Yes | No | No | No | proc ps compare | |
Sguil | 2017 | No | No | No | No | Yes | No | ||
Logwatch16 | 2017 | Yes17 | Yes18 | Yes | No | No | Yes | ||
Logcheck19 | 2017 | Yes20 | Yes21 | Yes | No | No | Yes | ||
Epylog22 | 2014 | Yes23 | Yes24 | Yes | No | No | Yes | ||
SWATCH25 | 2015 | Yes26 | Yes27 | Yes | No | No | Yes | ||
sagan | 2021 | Yes28 | No | No | No | No | Yes | ||
aide | 2023 | Yes29 | Yes30 | Yes | Yes | No | No | ||
tripwire | 2018 | Yes31 | Yes32 | Yes | Yes | No | No | ||
Tiger | 2018 | Yes33 | No | No | Yes | No | No | Yes | 3/42 modules are Debian specific. |
Proprietary software
Package | Year34 | Linux | Windows | File | Network | Logs | Config | Notes |
---|---|---|---|---|---|---|---|---|
Lacework | 2018 | Yes | No | Yes | Yes | Yes | Yes | |
Verisys | 2018 | Yes | Yes | Yes | Yes | Yes | ||
Nessus | 2017 | Yes | Yes | Yes | ||||
Atomicorp | 2019 | Yes | Yes | Yes | Yes | Yes | Yes | Commercially enhanced version of OSSEC |
Spartan | 2021 | No | Yes | Yes | Yes | Yes | Yes | Websocket API, IP to Country mapping, DynDNS Integration |
External links
References
"Downloads OSSEC". OSSEC. Retrieved 2017-10-19. OSSEC for Debian Based systems https://ossec.github.io/downloads.html#apt-automated-installation-on-ubuntu-and-debian ↩
"Downloads OSSEC". OSSEC. Retrieved 2017-10-29. OSSEC for RHEL/Fedora Based systems https://ossec.github.io/downloads.html#rhel-centos-fedora-and-others ↩
"ossec-hids". openSUSE OBS. Retrieved 2024-08-11. An Open Source Host-based Intrusion Detection System https://software.opensuse.org/package/ossec-hids ↩
"Samhain". Ubuntu. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=samhain ↩
"Samhain". openSUSE OBS. Retrieved 2024-08-11. File integrity and host-based IDS https://software.opensuse.org/package/samhain?search_term=Samhain ↩
Last ↩
"Snort". Ubuntu. Retrieved 2017-04-19. Snort in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=snort ↩
"Snort". Cisco Systems. Retrieved 2017-05-31. Snort in the CentOS Repositories https://pkgs.org/download/snort ↩
"ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=chkrootkit ↩
lastlog, wtmp, utmp, wtmpx ↩
"RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=rkhunter ↩
"RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the CentOS Repositories https://pkgs.org/download/rkhunter ↩
"unhide". debian. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora https://packages.debian.org/search?keywords=unhide ↩
"UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=unhide ↩
"UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the CentOS Repositories https://pkgs.org/download/unhide ↩
"Logwatch". debian. Retrieved 2017-04-17. Logwatch is notable because it's part of Debian and Fedora https://packages.debian.org/search?keywords=logwatch ↩
"LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=logwatch ↩
"LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the CentOS Repositories https://pkgs.org/download/logwatch ↩
"Logcheck". debian. Retrieved 2017-04-17. Logcheck is notable because it's part of Debian and Fedora https://packages.debian.org/search?keywords=logcheck ↩
"Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=logcheck ↩
"Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the CentOS Repositories https://pkgs.org/download/logcheck ↩
"Epylog". debian. Retrieved 2017-04-17. Epylog is notable because it's part of Debian and Fedora https://packages.debian.org/search?keywords=epylog ↩
"Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=epylog ↩
"Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the CentOS Repositories https://pkgs.org/download/epylog ↩
"SWATCH". debian. Retrieved 2017-04-17. SWATCH is notable because it's part of Debian and Fedora https://packages.debian.org/search?keywords=swatch ↩
"SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=swatch ↩
"SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the CentOS Repositories https://pkgs.org/download/swatch ↩
"Sagan". Ubuntu. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=sagan ↩
"AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=aide ↩
"AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the CentOS Repositories https://pkgs.org/download/aide ↩
"Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=tripwire ↩
"Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the CentOS Repositories https://pkgs.org/download/tripwire ↩
"Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories http://packages.ubuntu.com/search?keywords=tiger ↩
Last updated ↩