Linux Auditd & File Integrity Monitoring with AIDE
System integrity monitoring is essential to catch rootkits, persistence implants, and stealth tampering. Two native Linux defense tools form this baseline:
- AIDE (Advanced Intrusion Detection Environment): Records checksums and metadata for configured paths so later checks can identify changes.
- Auditd (Linux Audit Subsystem): Records selected kernel audit events, such as writes to identity and sudo configuration files. The rules below do not log every administrative command or all SSH activity.
The package commands below use Debian/Ubuntu. Other distributions use different package names and may have different service-management details.
Step 1: Install AIDE & Generate Clean Cryptographic Baseline
Initialize System Checksum Database
Run in Admin ModeInstall AIDE on a fresh or otherwise trusted Debian/Ubuntu system. Initialization writes a new database; the final install command copies it into the active path with root-only permissions. Protect a separate baseline copy outside this host so a root-level intruder cannot quietly replace both the system and its reference database.
sudo apt update && sudo apt install -y aide aide-common
# Initialize the baseline database:sudo aideinit
# Promote the newly created baseline to the active database:sudo install -o root -g root -m 0600 \ /var/lib/aide/aide.db.new /var/lib/aide/aide.dbsudo stat -c '%A %U:%G %n' /var/lib/aide/aide.db⯠View Expected Console Output
Running aide --init...New database: /var/lib/aide/aide.db.new-rw------- root:root /var/lib/aide/aide.dbStep 2: Run an On-Demand Integrity Check
Scan Filesystem for Unauthorized Modifications
Integrity ScanCompare the current filesystem state against the baseline. This step runs a check manually; it does not install a scheduler. Choose a scheduled AIDE check frequency separately if your monitoring policy requires one.
# Perform an immediate integrity comparison check:sudo aide --check⯠View Expected Console Output
AIDE 0.18 found NO differences between database and filesystem.System files match cryptographic baseline.Step 3: Install and Configure Auditd Kernel Rules
Deploy Real-Time Watch Rules for Critical Security Files
Run in Admin ModeInstall the Linux Audit daemon and monitor modifications to user credentials and sudo configuration:
sudo apt install -y auditd audispd-pluginssudo systemctl enable --now auditdsudo systemctl is-active auditdsudo systemctl is-enabled auditd
# Add persistent rules for writes and attribute changes to identity and sudoers files:sudo tee /etc/audit/rules.d/99-security-watches.rules << 'EOF'-a always,exit -F path=/etc/passwd -F perm=wa -k identity_changes-a always,exit -F path=/etc/shadow -F perm=wa -k identity_changes-a always,exit -F path=/etc/sudoers -F perm=wa -k priv_escalation-a always,exit -F dir=/etc/sudoers.d -F perm=wa -k priv_escalationEOF
# Load rules into the running Linux kernel:sudo augenrules --loadsudo auditctl -l⯠View Expected Console Output
activeenabled-a always,exit -F path=/etc/passwd -F perm=wa -F key=identity_changes-a always,exit -F path=/etc/shadow -F perm=wa -F key=identity_changes-a always,exit -F path=/etc/sudoers -F perm=wa -F key=priv_escalation-a always,exit -F dir=/etc/sudoers.d -F perm=wa -F key=priv_escalationStep 4: Search and Analyze Security Event Logs
Query Audit Events with ausearch and aureport
Forensic AuditSearch for audit triggers generated whenever monitored files were touched:
# Query audit events tagged with 'identity_changes':sudo ausearch -k identity_changes --format text
# Generate summary of authentication attempts and failed logins:sudo aureport -au --failed⯠View Expected Console Output
----time->Sat Oct 03 21:05:12 2026type=PATH msg=audit: item=0 name="/etc/passwd" inode=13245 dev=08:01 mode=0100644 ouid=0 ogid=0type=SYSCALL msg=audit: arch=c000003e syscall=257 success=yes exit=3 a0=ffffff9c comm="useradd" exe="/usr/sbin/useradd" key="identity_changes"