Key | Value |
---|---|
FileSize | 1178282 |
MD5 | 654F06B546A566D2FC462359AECA38D4 |
PackageDescription | Data integrity and host intrusion alert system Samhain is an integrity checker and host intrusion detection system that can be used on single hosts as well as large, UNIX-based networks. It supports central monitoring as well as powerful (and new) stealth features to run undetected on memory using steganography. . Main features * Complete integrity check + uses cryptographic checksums of files to detect modifications, + can find rogue SUID executables anywhere on disk, and * Centralized monitoring + native support for logging to a central server via encrypted and authenticated connections * Tamper resistance + database and configuration files can be signed + logfile entries and e-mail reports are signed + support for stealth operation |
PackageMaintainer | Javier Fernández-Sanguino Peña <jfs@debian.org> |
PackageName | samhain |
PackageSection | admin |
PackageVersion | 4.1.4-2+b1 |
SHA-1 | 28A077B2182C2D424A05448FB1F2AFABD9966212 |
SHA-256 | 94F819989010C8558675A806BBFBF11FEF5A96D90950FA9F2EBE2D783E94707B |
hashlookup:children-total | 267 |
hashlookup:trust | 50 |
The searched file hash includes 267 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
CRC32 | ED411D32 |
FileName | ./usr/share/xml/docbook/stylesheet/docbook-xsl/images/callouts/3.svg |
FileSize | 1067 |
MD5 | 2826467C386668C96B28864C42B3745B |
OpSystemCode | 362 |
ProductCode | 17075 |
RDS:package_id | 302124 |
SHA-1 | 0051494D8CF6F899FB49B4A71CF607E69FC68901 |
SHA-256 | AEE9CFDCE84F534199885405D90F980D294FFF3AD065DA380C8696A992BA40CD |
SHA-512 | 421F599E72AF50898E114C4B8D738CB4158D1E3487A3471ACFE5A1520B4FDD2C45EBD46B1F14C465E09FD66D6AE026DFF24168EAF23E6B0B551517169AD51C79 |
SSDEEP | 24:2d8nArsrCpViArUqgIL9oPadRPsZRgX2PH:c8nArsrOEArUqvqSdhDk |
SpecialCode | |
TLSH | T1681112498B4FD41CB1D0C671877137E7333555E8738A15B4E3872D3EB22A9946710EB8 |
db | nsrl_legacy |
insert-timestamp | 1728243985.9164813 |
mimetype | image/svg+xml |
nsrl-sha256 | rds241-sha256.zip |
source | snap:wequGIeqkgIkU8TkAMvejZtOFx9AIu0W_7 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
CRC32 | 37CB884A |
FileName | ./usr/share/xml/docbook/stylesheet/docbook-xsl/images/colorsvg/important.svg |
FileSize | 19817 |
MD5 | 4D37B2FA7BF8EE3230F6A195C5720270 |
OpSystemCode | 362 |
ProductCode | 12601 |
RDS:package_id | 302124 |
SHA-1 | 01473124ABDA665FFACF62D37F3E893B8BB2765E |
SHA-256 | A257F75F5A635B0D322BB588BC5E37DF8E173CD735EED2FFFAA4BAA84451873F |
SHA-512 | 6ED7A69D5AB271F758142BB048EA41C5D1954FF87B984585E7ADD08C53EA9BE73F28A05B51592E24793685352F67EFC49AA978ECD1FB21D50DAB6B15E075D1E9 |
SSDEEP | 192:GGga+9RF3e9YMRAuUQOaqXyiZpWpjDeZZ:GGDIzMRYQOvLDSXU |
SpecialCode | |
TLSH | T13E92D787330C9D7CFA3204B9E72532B3606B855535A475A48AF320798A2B34D6E7BCDD |
db | nsrl_legacy |
insert-timestamp | 1728243986.1102931 |
mimetype | image/svg+xml |
source | snap:wequGIeqkgIkU8TkAMvejZtOFx9AIu0W_7 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
CRC32 | 3BD43F4B |
FileName | ./usr/share/xml/docbook/stylesheet/docbook-xsl/images/colorsvg/warning.svg |
FileSize | 17106 |
MD5 | DE574DF7981BCB720860BE71EEBC610F |
OpSystemCode | 362 |
ProductCode | 12601 |
RDS:package_id | 302124 |
SHA-1 | 01D3B322C9D0B41ACBA2394D6B635172135D5FA0 |
SHA-256 | F95A3F6043822840D8E64BA811BE6EC29C7CBB01E728B17DAD5163B35894643C |
SHA-512 | F73C4AA177C2A3E77DFE02FD31EC6F7A5A52B0812EE837B58047068AFE1905688CD954DD7AF0C1E4FC42F9DB172E3634C7F56FE63C396438E192EE38AB511E9B |
SSDEEP | 192:GGwP8cyTKsF4RRPZCMJgG71oG7ioVmi8iYSGsFWd4+p1Y:GGwP8cgFABCnG7mG7i4mRiYSGuN |
SpecialCode | |
TLSH | T1B4721FD73B5897ECEA0048EEA13024CB32D7FC8978D06446D2C134567C5BAFE5EB496A |
db | nsrl_legacy |
insert-timestamp | 1728243986.0429413 |
mimetype | image/svg+xml |
source | snap:wequGIeqkgIkU8TkAMvejZtOFx9AIu0W_7 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
CRC32 | 128C30C7 |
FileName | ./usr/share/xml/docbook/stylesheet/docbook-xsl/images/callouts/14.svg |
FileSize | 906 |
MD5 | 821B4B1BFEBD42F747465153006EEF8F |
OpSystemCode | 362 |
ProductCode | 17075 |
RDS:package_id | 302124 |
SHA-1 | 0283713C0F75AEB9FF524268CECBCCEA3C76A735 |
SHA-256 | D1FAE5D438C33909D34190CE684E1F646420C7CAFD402008A6B251E1B0910E76 |
SHA-512 | E18008E287B2F8AD6465836439D526710586A6BF0E1F77F5363D38F5FDF3115D41AA48BC49ED6DE3AE279C256F8407414E6028FF6EA4B0532079DC411F4B834C |
SSDEEP | 24:2d8nArsrCpViArUqgIL9oWE1oAsPpVhQO93:c8nArsrOEArUqvqWjA2hQE3 |
SpecialCode | |
TLSH | T1FD114401DF098C2E60119360C3B566D723307CE8A38A69B9F21B6D39B7295541905DFC |
db | nsrl_legacy |
insert-timestamp | 1728243986.0281203 |
mimetype | image/svg+xml |
nsrl-sha256 | rds241-sha256.zip |
source | snap:wequGIeqkgIkU8TkAMvejZtOFx9AIu0W_7 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
CRC32 | 457AF023 |
FileName | ./usr/share/xml/docbook/stylesheet/docbook-xsl/images/home.png |
FileSize | 271 |
MD5 | E829AF9457BA497BA3048A8EDF2C0E08 |
OpSystemCode | 362 |
ProductCode | 187169 |
RDS:package_id | 182052 |
SHA-1 | 059754331DCCDA04688D1199B27F670DB25CF37A |
SHA-256 | 1E1A1876A4DC9824979CC1774182196F0FE1549C2A6C9353D713B63299F6E093 |
SSDEEP | 6:6v/lhP0wNtqMQyw/OaR7dgaxO9gIwkZiK5JDFkHiKml0bp:6v/7sjZ/OJ6SNZAHtS01 |
SpecialCode | |
TLSH | T174D0EBE483404C37EDC853290238A3A1ADB4C078CAE3BAEE1A5600626C9000BC2E4342 |
db | nsrl_modern_rds |
insert-timestamp | 1679425035.0732164 |
source | RDS.db |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
CRC32 | 87764A20 |
FileName | ./usr/share/xml/docbook/stylesheet/docbook-xsl/images/next.svg |
FileSize | 1040 |
MD5 | 3496D53341C155149EFA3175C8B2AD83 |
OpSystemCode | 362 |
ProductCode | 17075 |
RDS:package_id | 302124 |
SHA-1 | 06DA3A4241F97E05DB8F2E90EAA61F64C47B9384 |
SHA-256 | 167D09A5417B3A8260DDFAB304BC348DD5301E1016DA20DFA23D75EBE1C7547A |
SHA-512 | 4E34472D6BB196F3C5FE41393BD994AC32DBDD864C9AFCF9C089C34294591108923059089A2716A90763E71ADB571E10A6274C7D94FF6D04C0BE14B2161CE7B6 |
SSDEEP | 24:2dVJ0LrFYgiwbA8Qx1ZZ6ROd5NbsHhPiHRvEROd5NbsHhPiH4VKZ9X:cVJurFXWd1SOd/MFiHyOd/MFiH40T |
SpecialCode | |
TLSH | T18411AF1543488F6E829E8231E768F9C6E066ECC7668074F033471222F9B8AE42C5A4FC |
db | nsrl_legacy |
insert-timestamp | 1728243985.4671736 |
mimetype | image/svg+xml |
nsrl-sha256 | rds241-sha256.zip |
source | snap:wequGIeqkgIkU8TkAMvejZtOFx9AIu0W_7 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | ./etc/logrotate.d/samhain |
FileSize | 556 |
MD5 | AA5A1154B3F381D4A4B3B1C3636045D2 |
SHA-1 | 07928FC7EE79297F8B9F86ACD6E7FC1B78427689 |
SHA-256 | C24FBD85C18242B674EFF005BB6188ECE4BD7DA345B42B072F71F19C0928A08F |
SSDEEP | 6:EJInHaFNaIlMvdNQ2FFUZtefWAW717nRYnKSzBmFlMB1FxXMJLQAW71ynmOePFVW:gIaOdNd/U2fHW4zBylA56W4mLICzbW |
TLSH | T1ADF0E54D26413E213BE0C82E4D3B9A8922434077ED661D2279CDF7A6DF4F15472A4365 |
Key | Value |
---|---|
CRC32 | 0CD829C3 |
FileName | ./usr/share/xml/docbook/stylesheet/docbook-xsl/images/callouts/7.gif |
FileSize | 907 |
MD5 | 3B65F2E2286842F3DF086D355ACEB01B |
OpSystemCode | 362 |
ProductCode | 17075 |
RDS:package_id | 302124 |
SHA-1 | 079D7BD2561BC0D4921DC3842071D6BFE8CAA68B |
SHA-256 | 3A3F2E5FA85BCA0E33C9FE947820658177AE754EB212782F863BC1D55119357B |
SHA-512 | 87ECAC60EC60558770E5BB489F6486401370B54B84EBA13C55D67BAB5311B6B708F94E15C85BA42137F98E7B0BDFA4D4C05D327EED041BB165CD7B8F1C21ED69 |
SSDEEP | 24:HIIsQAQ8Ic44Yo4bo4Y4ofXQLo4LoXgMXI7gAgXIL115qdO:HI3nfXP3nfXfX/HXPX/HXa1P |
SpecialCode | |
TLSH | T10A1163D0E2B8D5132CF1967899C08F62CC84295428631F8DF6AB24846649F592E6D23E |
db | nsrl_legacy |
insert-timestamp | 1728243985.7453668 |
mimetype | image/gif |
nsrl-sha256 | rds241-sha256.zip |
source | snap:wequGIeqkgIkU8TkAMvejZtOFx9AIu0W_7 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | ./usr/share/doc/samhain/changelog.gz |
FileSize | 39774 |
MD5 | C0F780E583E57472C98F94EB84FAEE64 |
SHA-1 | 08DE27869831103994D1A2E39EA1A0A09C41C17B |
SHA-256 | 55A84BBAD8AF36AF17A976D839D2F17D99C7E9356288751C204E1AD81557F744 |
SSDEEP | 768:BuCM4GCDSVGoNbNwQjAtBLK/H0/GjWqelGEd8ygbe63/Td+:ZGfV1BNpUtBLj3q+GPJbe63/TI |
TLSH | T1DA03F196567B14BFD181B2A2F7FD034AB722A5624640B4D40FE587DB076E0D3A3CCB86 |
Key | Value |
---|---|
FileName | ./usr/share/doc/samhain/manual.html/signed-installation.html |
FileSize | 3923 |
MD5 | 57D44FE9E70D311574EF4CC2920856E4 |
SHA-1 | 0927925B6ECE29323A1F090D1DD61110D72726C1 |
SHA-256 | 34E3E21325D9CDEA876A7B947BABFFF3F0DA66DF3C8791222A1004CC7B30CF46 |
SSDEEP | 96:EHDXXO48NO48gMDackaBV480eGiuWxvArfhAW0J2okAvYC9AaUaxoyZ48tl4Q+:EG0gMD1uiuWZArfhAW0J2PA3m61LN+ |
TLSH | T1C4812E67D5A167372A130AEEC2D06FB9BCFEA14E92B104903CEFE3294781D946733545 |