linux-intrusion-detection
Installation
SKILL.md
Intrusion Detection
Distro support
Two-family skill. fail2ban and the rootkit scanners (rkhunter, chkrootkit)
run on both families; install and a couple of paths differ, and the RHEL
family adds SELinux AVC denials as an intrusion signal. Body uses
Debian/Ubuntu; substitute per this matrix. auditd and AIDE moved to
15-compliance-and-auditing — see linux-auditd-rules and
linux-file-integrity.
| Concept | Debian/Ubuntu | RHEL family |
|---|---|---|
| fail2ban install | apt install fail2ban |
dnf install fail2ban (EPEL on RHEL/Rocky/Alma; main on Fedora) |
| fail2ban backend | reads /var/log/auth.log |
reads journald / /var/log/secure (use backend = systemd) |
| rkhunter / chkrootkit | apt install rkhunter chkrootkit |
dnf install rkhunter chkrootkit (EPEL on RHEL/Rocky/Alma/Oracle; main on Fedora) |
| Rootkit scan auto-run | /etc/cron.daily/rkhunter + /etc/default/rkhunter |
no packaged wrapper — use systemd timer / cron |
| MAC denials as IDS signal | AppArmor (journalctl -k | grep apparmor) |
SELinux AVC (ausearch -m AVC, aureport --avc) |
| Web/auth log paths | /var/log/auth.log |
/var/log/secure |