1. Does ossec File integrity checking, generate hashes for files in the
selected directories when initially installed?
- if yes:
- where is the database with the hashes?
- can ossec use hashes generated by my package mgmt process..
(debian (debsums -a ) for example)?
- are the file hashes signed or is there a signed database hash?
2. I assume that when files from a monitored directory are created/deleted,
File Integrity checking will catch/report it as well.... yes?
3. how are signatures (rootkit, SIM/SIEM) updated? Is there an automated way
to do this... cron maybe?
R
--
Richard Geddes
BlueGolf - www.BlueGolf.com
[email protected] | 610-293-0998 | 610-293-0987 (fax)