3 ms·
What AV (if any?) would people recommend for linux? I feel that clamav is more for incoming files than something which would or could catch this?
by c16 2y ago
What AV (if any?) would people recommend for linux? I feel that clamav is more for incoming files than something which would or could catch this?
- INTPenis 2y agoNone, I would instead recommend monitoring file paths and alerting when they change. Known as a tripwire system. In this case for example the attackers tried to hide their files by disguising them as other known file paths on the system. If you use a tripwire setup you will get an alert when a file appears that is not supposed to be there. Of course this requires a more hands-on approach where you create excludes for all your applications.
- internet_points 2y agoAny tools or resources you'd recommend for this?
- INTPenis 2y agoI favor Red Hat and I know we use ossec at work. I believe you can use it under a free license but the configuration is rather complex imho. There is also snort which is a more libre project, but it's more of a full featured IDS that try to sell subscriptions for patterns. Think of them sort of like virus definitions but for rootkits and intrusions. You can technically setup Snort as a tripwire. A tripwire is very simple, some people have made them from scratch using Cronjobs and shell scripts. They simply maintain a database of all your files and their checksums, and alert you when a checksum changes. But security is more than just an IDS. I would recommend SElinux+IDS+remote logging+MFA+granular user security and more!
- lowleveldesign 2y agoThere is also Sysmon for Linux [1]. I work often with Windows systems that's how I know it (it's a popular choice on Windows to analyze Sysmon logs for suspicious events), but it's probably niche in Linux world. [1] https://github.com/microsoft/SysmonForLinux https://github.com/microsoft/SysmonForLinux