Download List

Project Description

samhain is a daemon that can check file integrity, search the file tree for SUID files, and detect kernel module rootkits (Linux only). It can be used either standalone or as a client/server system for centralized monitoring, with strong (192-bit AES) encryption for client/server connections and the option to store databases and configuration files on the server. For tamper resistance, it supports signed database/configuration files and signed reports/audit logs. It has been tested on Linux, FreeBSD, Solaris, AIX, HP-UX, and Unixware.

System Requirements

System requirement is not defined
Information regarding Project Releases and Project Resources. Note that the information here is a quote from Freecode.com page, and the downloads themselves may not be hosted on OSDN.

2009-01-30 07:13
2.5.2

This release provides a new option to avoid reports for timestamp changes on directories. For open ports, PID is determined now, and reporting of open ports to prelude has been improved. A bug has been fixed that could cause truncation of the reported file size upon entering into an RDBMS, and some build problems have been fixed.
Tags: Minor feature enhancements

2008-12-18 06:40
2.5.1

The syntax for conditionals in the configuration file has been enhanced. An option has been added to drop checksummed files from the file cache. The server can now request on-demand scans from the clients. Some compile issues and a problem with reloading the configuration in stealth mode have been fixed.
Tags: Minor feature enhancements

2008-11-04 06:52
2.5.0

This version provides a new module to perform log file monitoring (currently supported: syslog, apache, samba, and pacct). On Linux, port monitoring now reports the process and the user for open ports. Some minor bugs have been fixed.
Tags: Major feature enhancements

2008-09-03 13:34
2.4.6

This release fixes a potential deadlock (if dnmalloc is enabled), a compile problem on Win2k/Cygwin, and a portability problem with the regression tests.
Tags: Minor bugfixes

2008-08-19 05:33
2.4.5

This release includes the dnmalloc allocator, which is used as the default allocator but can be dropped at compile time. Some minor bugs have been fixed.
Tags: Minor feature enhancements

Project Resources