Back to tutorials
Key takeaways
- Tripwire builds a baseline: an encrypted database of cryptographic signatures (such as SHA-256) for the monitored files, stored in
/var/lib/tripwire/and created bysudo tripwire --init. - That baseline is only worth anything if it is taken on a known-clean system: installing Tripwire on an already compromised server amounts to certifying the backdoor as legitimate.
- Two separate passphrases protect the tool: the site key, requested at initialisation, and the local key, requested to read the reports produced by
tripwire --check. They are what prevents tampering with the database and the configuration. - The policy file
/etc/tripwire/twpol.txtdecides which files are watched and which attributes are compared (permissions, hash, size). It is the only real lever against report noise. - After a legitimate change you must accept the modifications with
tripwire --update --twrfile /var/lib/tripwire/report/YOUR_REPORT.twr, otherwise they reappear in every subsequent report.
What is Tripwire?
Tripwire is a Host-based Intrusion Detection System (HIDS) and a File Integrity Monitoring (FIM) tool. Its operation is simple in theory: it creates a "baseline", a database containing the cryptographic signatures (such as SHA-256) of important files and directories. Then, at regular intervals, it compares the current state of the files against this baseline to detect any modification, deletion, or addition.
Tripwire is a Host-based Intrusion Detection System (HIDS) and a File Integrity Monitoring (FIM) tool. Its operation is simple in theory: it creates a "baseline", a database containing the cryptographic signatures (such as SHA-256) of important files and directories. Then, at regular intervals, it compares the current state of the files against this baseline to detect any modification, deletion, or addition.
Why use Tripwire?
- Compromise detection: If an attacker modifies a system binary (e.g.
/bin/ls) to hide their tracks, Tripwire will detect it. - Compliance: Many security standards (PCI-DSS, HIPAA) require file integrity monitoring. Tripwire is a perfect tool for this.
- Change control: Lets you ensure that only authorized changes are made to production servers.
Prerequisites
- A Linux server (Ubuntu/Debian, CentOS/RHEL) in a known "clean" state. It is crucial to install Tripwire before the server is potentially compromised.
- Root access or sudo privileges.
Premium Content
This advanced tutorial is reserved for premium members.
9,90€ / month
- All advanced tutorials
- New content every week
- Progress tracking
- Cancel anytime