Digitally Fingerprint Your Files

Chris Binnie · 2016

This chapter covers attack vector, rootkits, and a fantastic piece of software called Rootkit Hunter. It also explores how to monitor filesystem's important files, such as its executables. Tripwire ran periodically and used cryptographic hashing to monitor any file changes on the system. After operating system (OS) installation and run that through the requisite postinstall fine-tuning, consider recording the MD5sums of key system files. The chapter further reviews a different approach to file fingerprinting. To receive overnight reports on the integrity of machine, one just need to edit two config parameters, one defining the e-mail address of the recipient and the latter of which is adjustable if the standard mail command won't work on the system by default. If one receive any false positives, then whitelist them within the config file. We should keep in mind that any hidden files or directories are almost always suspicious to filesystem scanners.

Read the paper · More papers on PaperTik