The Samhain host-based intrusion detection system (HIDS) provides file integrity checking and log file monitoring/analysis, as well as rootkit detection, port monitoring, detection of rogue SUID executables, and hidden processes.
Samhain been designed to monitor multiple hosts with potentially different operating systems, providing centralized logging and maintenance, although it can also be used as standalone application on a single host.
This is free and open source software.
Key Features
- Centralized monitoring – the client/server architecture allows central logging, central storage of baseline databases and client configurations, and central updates of baseline databases.
- Web-based management console is available separately – Beltane allows you to monitor server and client activity, view client reports, and update the baseline databases.
- Flexible logging – supports multiple logging facilities, each of which can be configured individually.
- Tamper resistance – offers PGP-signed database and configuration files, a stealth mode, and several more features to protect its integrity.
- The client (or standalone) part is called samhain, while the server is referred to as yule. Both can run as daemon processes.
- Cross-platform support – runs under Linux, macOS, and Windows.
Website: www.la-samhna.de/samhain
Support: User Manual
Developer: Samhain Labs
License: GNU General Public License v2.0
Samhain is written in C. Learn C with our recommended free books and free tutorials.
Related Software
| Host-Based Intrusion Detection Systems | |
|---|---|
| Wazuh | Platform used for threat prevention, detection, and response |
| OSSEC | Full platform to monitor and control your systems. |
| AIDE | Advanced Intrusion Detection Environment |
| Logwatch | Powerful and versatile log parser and analyzer |
| Samhain | File integrity checking and log file monitoring/analysis and more |
| Sagan | Multi-threads, high performance log analysis engine |
| Tripwire | Security and data integrity tool |
| rkhunter | Scans for rootkits, backdoors and possible local exploits |
| chkrootkit | Locally checks for signs of a rootkit |
Read our verdict in the software roundup.
Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more. Discovered a useful open source Linux program that we haven’t covered yet? Let us know by completing this form. |


Sounds like an interesting project or tool. However, it seems that the tool is not being maintained very well, if you take a look at the project’s user forum.
Is there anything similar or an alternative to Samhain that is still being maintained and developed? Do you know of anything?
I don’t see anything on their forums to support this.
It seems like the project is maintained, last release is May 2023.