Skip to content

Linux Auditd & File Integrity Monitoring with AIDE

System integrity monitoring is essential to catch rootkits, persistence implants, and stealth tampering. Two native Linux defense tools form this baseline:

  1. AIDE (Advanced Intrusion Detection Environment): Records checksums and metadata for configured paths so later checks can identify changes.
  2. Auditd (Linux Audit Subsystem): Records selected kernel audit events, such as writes to identity and sudo configuration files. The rules below do not log every administrative command or all SSH activity.

The package commands below use Debian/Ubuntu. Other distributions use different package names and may have different service-management details.


Step 1: Install AIDE & Generate Clean Cryptographic Baseline

01

Initialize System Checksum Database

Run in Admin Mode

Install AIDE on a fresh or otherwise trusted Debian/Ubuntu system. Initialization writes a new database; the final install command copies it into the active path with root-only permissions. Protect a separate baseline copy outside this host so a root-level intruder cannot quietly replace both the system and its reference database.

Terminal window
sudo apt update && sudo apt install -y aide aide-common
# Initialize the baseline database:
sudo aideinit
# Promote the newly created baseline to the active database:
sudo install -o root -g root -m 0600 \
/var/lib/aide/aide.db.new /var/lib/aide/aide.db
sudo stat -c '%A %U:%G %n' /var/lib/aide/aide.db
❯ View Expected Console Output
Running aide --init...
New database: /var/lib/aide/aide.db.new
-rw------- root:root /var/lib/aide/aide.db

Step 2: Run an On-Demand Integrity Check

02

Scan Filesystem for Unauthorized Modifications

Integrity Scan

Compare the current filesystem state against the baseline. This step runs a check manually; it does not install a scheduler. Choose a scheduled AIDE check frequency separately if your monitoring policy requires one.

Terminal window
# Perform an immediate integrity comparison check:
sudo aide --check
❯ View Expected Console Output
AIDE 0.18 found NO differences between database and filesystem.
System files match cryptographic baseline.

Step 3: Install and Configure Auditd Kernel Rules

03

Deploy Real-Time Watch Rules for Critical Security Files

Run in Admin Mode

Install the Linux Audit daemon and monitor modifications to user credentials and sudo configuration:

Terminal window
sudo apt install -y auditd audispd-plugins
sudo systemctl enable --now auditd
sudo systemctl is-active auditd
sudo systemctl is-enabled auditd
# Add persistent rules for writes and attribute changes to identity and sudoers files:
sudo tee /etc/audit/rules.d/99-security-watches.rules << 'EOF'
-a always,exit -F path=/etc/passwd -F perm=wa -k identity_changes
-a always,exit -F path=/etc/shadow -F perm=wa -k identity_changes
-a always,exit -F path=/etc/sudoers -F perm=wa -k priv_escalation
-a always,exit -F dir=/etc/sudoers.d -F perm=wa -k priv_escalation
EOF
# Load rules into the running Linux kernel:
sudo augenrules --load
sudo auditctl -l
❯ View Expected Console Output
active
enabled
-a always,exit -F path=/etc/passwd -F perm=wa -F key=identity_changes
-a always,exit -F path=/etc/shadow -F perm=wa -F key=identity_changes
-a always,exit -F path=/etc/sudoers -F perm=wa -F key=priv_escalation
-a always,exit -F dir=/etc/sudoers.d -F perm=wa -F key=priv_escalation

Step 4: Search and Analyze Security Event Logs

04

Query Audit Events with ausearch and aureport

Forensic Audit

Search for audit triggers generated whenever monitored files were touched:

Terminal window
# Query audit events tagged with 'identity_changes':
sudo ausearch -k identity_changes --format text
# Generate summary of authentication attempts and failed logins:
sudo aureport -au --failed
❯ View Expected Console Output
----
time->Sat Oct 03 21:05:12 2026
type=PATH msg=audit: item=0 name="/etc/passwd" inode=13245 dev=08:01 mode=0100644 ouid=0 ogid=0
type=SYSCALL msg=audit: arch=c000003e syscall=257 success=yes exit=3 a0=ffffff9c comm="useradd" exe="/usr/sbin/useradd" key="identity_changes"

Comments