AlmaLinux9.3 ; Suricata , Tripwire , Chkrootkit
Suricata
SURICATA IDS/IPS is an open source IDS that monitors communications on the network and detects suspicious traffic.
The basic mechanism is signature-based, so it can detect predefined unauthorized communications. Suricata is also characterized by its ability to provide protection as well as detection.
1.advance preparation
①Activate the EPEL Repository
Tripwire
1.Installation
# dnf install -y tripwire
Chkrootkit
①Download and install chkrootkit