Host-based intrusion detection system comparison explained
Comparison of host-based intrusion detection system components and systems.
As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.
Package | Year[34] | Linux | Windows | File | Network | Logs | Config | Notes |
---|
Lacework | 2018 | | | | | | | |
Verisys | 2018 | | | | | | | |
Nessus | 2017 | | | | | | | |
Atomicorp | 2019 | | | | | | | Commercially enhanced version of OSSEC |
Spartan | 2021 | | | | | | | Websocket API, IP to Country mapping, DynDNS Integration | |
References
- Web site: Downloads OSSEC. OSSEC. 2017-10-19 . OSSEC for Debian Based systems
- Web site: Downloads OSSEC. OSSEC. 2017-10-29 . OSSEC for RHEL/Fedora Based systems
- Web site: ossec-hids. openSUSE OBS. 2024-08-11 . An Open Source Host-based Intrusion Detection System
- Web site: Samhain . Ubuntu . 2017-04-19 . Samhain in the Ubuntu Repositories
- Web site: Samhain . openSUSE OBS. 2024-08-11 . File integrity and host-based IDS
- Last
- Web site: Snort . Ubuntu . 2017-04-19 . Snort in the Ubuntu Repositories
- Web site: Snort . Cisco Systems . 2017-05-31 . Snort in the CentOS Repositories
- Web site: ChkRootkit . Ubuntu . 2017-04-19 . ChkRootkit in the Ubuntu Repositories
- lastlog, wtmp, utmp, wtmpx
- Web site: RKHunter . Ubuntu . 2017-04-19 . RKHunter in the Ubuntu Repositories
- Web site: RKHunter . Ubuntu . 2017-04-19 . RKHunter in the CentOS Repositories
- Web site: unhide . debian . 2017-04-17 . unhide is notable because it's part of Debian and Fedora
- Web site: UnHide . Ubuntu . 2017-04-19 . UnHide in the Ubuntu Repositories
- Web site: UnHide . Ubuntu . 2017-04-19 . UnHide in the CentOS Repositories
- Web site: Logwatch . debian . 2017-04-17 . Logwatch is notable because it's part of Debian and Fedora
- Web site: LogWatch . Ubuntu . 2017-04-19 . LogWatch in the Ubuntu Repositories
- Web site: LogWatch . Ubuntu . 2017-04-19 . LogWatch in the CentOS Repositories
- Web site: Logcheck . debian . 2017-04-17 . Logcheck is notable because it's part of Debian and Fedora
- Web site: Logcheck . Ubuntu . 2017-04-19 . Logcheck in the Ubuntu Repositories
- Web site: Logcheck . Ubuntu . 2017-04-19 . Logcheck in the CentOS Repositories
- Web site: Epylog . debian . 2017-04-17 . Epylog is notable because it's part of Debian and Fedora
- Web site: Epylog . Ubuntu . 2017-04-19 . Epylog in the Ubuntu Repositories
- Web site: Epylog . Ubuntu . 2017-04-19 . Epylog in the CentOS Repositories
- Web site: SWATCH . debian . 2017-04-17 . SWATCH is notable because it's part of Debian and Fedora
- Web site: SWATCH . Ubuntu . 2017-04-19 . SWATCH in the Ubuntu Repositories
- Web site: SWATCH . Ubuntu . 2017-04-19 . SWATCH in the CentOS Repositories
- Web site: Sagan . Ubuntu . 2017-04-19 . Sagan in the Ubuntu Repositories
- Web site: AIDE . Ubuntu . 2017-04-19 . AIDE in the Ubuntu Repositories
- Web site: AIDE . Ubuntu . 2017-04-19 . AIDE in the CentOS Repositories
- Web site: Tripwire . Ubuntu . 2017-04-19 . Tripwire in the Ubuntu Repositories
- Web site: Tripwire . Ubuntu . 2017-04-19 . Tripwire in the CentOS Repositories
- Web site: Tripwire . Ubuntu . 2017-04-19 . Tripwire in the Ubuntu Repositories
- Last updated
External links