Intrusion Detection

Samhain – host-based intrusion detection system

The Samhain host-based intrusion detection system (HIDS) provides file integrity checking and log file monitoring/analysis, as well as rootkit detection, port monitoring, detection of rogue SUID executables, and hidden processes.

Samhain been designed to monitor multiple hosts with potentially different operating systems, providing centralized logging and maintenance, although it can also be used as standalone application on a single host.

This is free and open source software.

Key Features

  • Centralized monitoring – the client/server architecture allows central logging, central storage of baseline databases and client configurations, and central updates of baseline databases.
  • Web-based management console is available separately – Beltane allows you to monitor server and client activity, view client reports, and update the baseline databases.
  • Flexible logging – supports multiple logging facilities, each of which can be configured individually.
  • Tamper resistance – offers PGP-signed database and configuration files, a stealth mode, and several more features to protect its integrity.
  • The client (or standalone) part is called samhain, while the server is referred to as yule. Both can run as daemon processes.
  • Cross-platform support – runs under Linux, macOS, and Windows.

Website: www.la-samhna.de/samhain
Support: User Manual
Developer: Samhain Labs
License: GNU General Public License v2.0

Samhain is written in C. Learn C with our recommended free books and free tutorials.


Related Software

Host-Based Intrusion Detection Systems
WazuhPlatform used for threat prevention, detection, and response
OSSECFull platform to monitor and control your systems.
AIDEAdvanced Intrusion Detection Environment
LogwatchPowerful and versatile log parser and analyzer
SamhainFile integrity checking and log file monitoring/analysis and more
SaganMulti-threads, high performance log analysis engine
TripwireSecurity and data integrity tool
rkhunterScans for rootkits, backdoors and possible local exploits
chkrootkitLocally checks for signs of a rootkit

Read our verdict in the software roundup.


Best Free and Open Source Software Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.

This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk.

You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more.

Discovered a useful open source Linux program that we haven’t covered yet? Let us know by completing this form.
Subscribe
Notify of
guest
3 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
BigChief
BigChief
1 year ago

Sounds like an interesting project or tool. However, it seems that the tool is not being maintained very well, if you take a look at the project’s user forum.
Is there anything similar or an alternative to Samhain that is still being maintained and developed? Do you know of anything?

Treeman
Treeman
1 year ago
Reply to  BigChief

I don’t see anything on their forums to support this.