OSSEC is an open-source file integrity monitoring application that records changes to a server's file system to help detect and investigate an intrusion or change. It logs changes to monitored files on the system, and those logs should then be forwarded to centralized logging. This change information can be extremely useful for investigating security incidents. Additionally, OSSEC generates other security logs of system activity, which provide valuable insight to system administrators.
Stanford administrative and academic departments
- A Linux server (compiler needed to build from source)
- Also supported on other Unix variants
May be used with Low, Moderate, and High Risk Data, as defined by the Information Security Office
Free of charge
- Instead of OSSEC, install CrowdStrike
For assistance, submit a Help request