AlmaLinux 9.1 ; Suricata , Tripwire , Chkrootkit
Suricata
SURICATA IDS/IPS is an open source IDS that monitors communications on the network and detects suspicious traffic.
The basic mechanism is signature-based, so it can detect predefined unauthorized communications. Suricata is also characterized by its ability to provide protection as well as detection.
1.advance preparation
①Activate the EPEL Repository
# dnf -y install epel-release
Tripwire
1.Download and installation
# cd /usr/local/src
# wget https://rpmfind.net/linux/epel/9/Everything/x86_64/Packages/t/tripwire-2.4.3.7-13.el9.x86_64.rpm
# rpm -Uvh tripwire-2.4.3.7-13.el9.x86_64.rpm
Chkrootkit
①Download and install chkrootkit
# cd /usr/local/src
# wget https://launchpad.net/chkrootkit/main/0.55/+download/chkrootkit-0.55.tar.gz
# tar xvf chkrootkit-0.55.tar.gz