Hi everybody, I was discussing some security issues wit my colleagues. And we found interresting issue. How is guaranteed integrity of Ossec itself? Can Ossec somehow discover, that an attacker will replace Ossec with modified application. Modified Ossec will report during syscheck scan same size, modification times, checksums, etc. as had original version of Ossec application. Is there any internal mechanism howto prevent or discover described situation?
Jakub
