Tripwire is a file integrity monitoring (FIM) tool: it takes a cryptographic snapshot of a defined set of files and directories, then reports anything that changed — added, removed, or modified — on later checks. It is one of the original tools in this space (commercial and open-source editions both exist); AIDE is a common lighter-weight open-source alternative with a similar purpose.
Install¶
sudo apt-get install tripwire # Debian/Ubuntu; installer prompts to generate site/local keys interactively
sudo dnf install tripwire # RHEL family (may need EPEL)
The package installer walks through creating a site key (protects the policy and config files) and a local key (protects the database and reports) with passphrases — write these passphrases down somewhere safe; losing them means rebuilding the whole setup.
Policy and configuration¶
/etc/tripwire/twpol.txt— the policy: which files/directories to watch and which properties matter for each (permissions, size, hashes, timestamps)./etc/tripwire/twcfg.txt— general configuration (database/report locations, mail settings for alerts).
Both plain-text sources are compiled into signed binary files (tw.pol, tw.cfg) so they cannot be silently edited by an attacker:
sudo twadmin --create-polfile -S site.key /etc/tripwire/twpol.txt
sudo twadmin --create-cfgfile -S site.key /etc/tripwire/twcfg.txt
After hand-editing the plain-text policy, recompile it the same way and reinitialize the database (below) so the new rules take effect.
Initialize the baseline database¶
sudo tripwire --init
# prompts for the local passphrase; produces /var/lib/tripwire/<hostname>.twd
This is the trusted snapshot everything else is compared against. Do this right after installing the OS and hardening it — a baseline taken after a system is already compromised is worthless.
Run a check¶
sudo tripwire --check # full check against the policy, prints a report
sudo tripwire --check --interactive # lets you accept/reject each change as you go
sudo tripwire --check | mail -s "Tripwire report: $(hostname)" [email protected]
Schedule this via cron, typically nightly, and mail or forward the report somewhere it will actually be read.
Updating the database after a legitimate change¶
Every real change (a patched binary, an intended config edit) needs to be accepted into the database, or every future check will keep flagging it:
sudo tripwire --update --twrfile /var/lib/tripwire/report/<hostname>-<date>.twr
This opens the report in an editor; leave the checkbox next to entries you want accepted, remove the checkbox (comment out with x in the box) for ones you don't, save, and Tripwire updates the database accordingly.
What it is (and isn't) good for¶
Tripwire tells you that something under policy changed and roughly what, checked at whatever interval you run it — it is not real-time, and it does not stop the change from happening. Pair it with auditd for real-time, syscall-level tracking of who made a change, and fail2ban or AppArmor for prevention rather than detection.